Cisco FMC CVE-2026-20079: Sandworm-linked and Qilin clusters hit firewall management for root

By George Bailey   Published: 09/10/26   Updated: 09/10/26   3 min read

What Changed

Cisco Talos confirmed on September 9–10 that three intrusion clusters are actively abusing Cisco Secure Firewall Management Center (FMC) web-interface flaws that yield management-plane footholds—and, for the lead bug, root on the underlying OS. CVE-2026-20079 is an authentication bypass caused by an improper system process created at boot time. An unauthenticated remote attacker who can reach the FMC web interface sends crafted HTTP requests and can execute scripts and commands that grant root on the device. Cisco discovered it internally, disclosed and fixed it in early March 2026 (advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2), and on September 9 stated it became aware of active exploitation dating to August. CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog the same day with a three-day BOD 26-04 window and forensic-triage requirements.

CVE-2026-20316 is related in-the-wild context only: static credentials for a low-privileged built-in account, disclosed with fixes around July 29 and previously flagged for exploitation. It is not the lead CVE for this brief, but Talos’s clusters use one or both bugs depending on the actor.

Talos cluster names, as reported: UAT-12197 exploits CVE-2026-20079 and plants a JSP web shell in the CSM Tomcat webroot, then drops a malicious JAR used to pull authentication data and credentials. UAT-11823 shows tooling overlap / TTP-consistent activity with Sandworm (Cyclops Blink–family implant behavior after initial access via one of the two FMC flaws). UAT-11988 is TTP-consistent with a Qilin ransomware affiliate pattern—static-credential login via CVE-2026-20316, living-off-the-land recon, credential theft, AV killers, and ransomware delivery. Report the cluster IDs as Talos named them; do not overclaim courtroom attribution from tooling overlap alone.

Why This Matters Operationally

FMC is the management plane for Cisco Secure Firewall estates. Compromising it is not “another appliance bug”—it is policy control, logging visibility, and credential material for every managed firewall. Root on FMC plus harvested managed-device configs is a perimeter rewrite waiting to happen. Pairing a CVSS 10.0 auth bypass now in KEV with concurrent static-credential abuse explains why both nation-state–style and ransomware-shaped clusters showed up on the same surface. Internet-exposed FMC management interfaces remain the highest-risk deployment pattern.

What Defenders Should Verify First

Source Context

The operational conclusion: patch FMC for CVE-2026-20079 today, pull management off the Internet, and forensically triage anything that was reachable—Sandworm-consistent and Qilin-consistent clusters are already on this surface.

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.