Cisco FMC Vulnerabilities Exploited by Nation-State and Ransomware Actors
Cisco has confirmed that its Secure Firewall Management Center (FMC) software contains two vulnerabilities that have been exploited in the wild. The bugs, identified as CVE-2026-20079 and CVE-2026-20316, allow attackers to bypass authentication and gain access to devices.
The first vulnerability, CVE-2026-20079, was discovered by Brandon Sakai of Cisco during internal security testing and fixed in early March 2026. It allows remote, unauthenticated attackers to execute scripts and commands that grant root access to the device. The second bug, CVE-2026-20316, stems from static (hard-coded) credentials for a low-privileged account, allowing unauthenticated, remote attackers to log in to an affected device/instance.
Cisco's threat intelligence analysts have identified three intrusion clusters leveraging one or both of these flaws. The first cluster exploits CVE-2026-20079 and places a malicious web shell on the CSM Tomcat webroot directory. The second cluster, believed to be the work of Russian state-sponsored group Sandworm, starts with attackers gaining access via one of the two vulnerabilities and then updating the license.tmp file with a malicious copy.
The third intrusion cluster, suspected to be the work of a Qilin ransomware operator, logs in with the static credentials (CVE-2026-20316), performs network and endpoint reconnaissance, steals credentials, establishes additional access, and delivers the ransomware. Cisco is advising customers to apply hotfixes for affected software versions already released by the company.