Talos Identifies Exploits on Cisco Secure Firewall Management Center Software
Cisco's Secure Firewall Management Center (FMC) Software has been found to be vulnerable to two critical exploits, according to Cisco Talos. CVE-2026-20079 is an authentication bypass vulnerability that allows remote attackers to gain root access to the underlying operating system. Meanwhile, CVE-2026-20316 enables attackers to log in using low-privileged accounts.
Talos has identified three clusters of post-compromise activity on FMC instances, attributed to state-sponsored and crimeware threat actors. The first cluster involves the exploitation of CVE-2026-20079, leading to the deployment of web shells and credential exfiltration. In the second cluster, attackers exploited both vulnerabilities to deploy a Netcat-based reverse shell and proxy tooling, ultimately installing Cyclops Blink malware.
A third cluster of malicious activity was attributed to UAT-11988, a Qilin ransomware operator. The threat actor gained access using static credentials (CVE-2026-20316) and used legitimate FMC tooling to conduct reconnaissance, deploy tunneling tools, and build a list of target endpoints for encryption.
Cisco has released hotfixes for affected software versions and advises customers to apply them immediately. A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 14th).