Cisco Talos has disclosed active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center, CVE-2026-20079 and CVE-2026-20316, with observed attacks linked to both advanced threat actors and ransomware operations. CVE-2026-20079 is the more severe of the two, carrying a maximum CVSS score of 10.0. It is an authentication-bypass vulnerability in the FMC web interface that allows an unauthenticated remote attacker to send crafted HTTP requests, bypass authentication, execute scripts, and ultimately obtain root access to the underlying operating system. Cisco says the vulnerability results from an improper system process created at boot time and affects Secure FMC Software regardless of configuration. Cisco confirmed active exploitation in August 2026 and has released hotfixes for affected 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 branches. There are no workarounds that fully address the flaw.
CVE-2026-20316 looks much less alarming if one looks only at its CVSS score of 5.3, but the exploitation observed by Talos demonstrates precisely why severity numbers should never be considered in isolation. The flaw exists because Cisco FMC contains static credentials for a low-privileged account. An unauthenticated remote attacker can use those credentials to log in and access sensitive information. Cisco deliberately rates the advisory High despite the relatively modest CVSS score because the low-privileged access can be combined with other FMC vulnerabilities to elevate privileges. Cisco PSIRT became aware of active exploitation of this flaw in July 2026, and Talos has now observed it being used as part of real intrusion chains.
The combination of the two vulnerabilities is important because it shows two different paths toward control of a highly privileged security-management platform. CVE-2026-20079 can provide direct unauthenticated root access, while CVE-2026-20316 gives attackers a legitimate low-privilege session that can be chained with other weaknesses or abused through functionality already available on the device. The second case is particularly instructive because the attack may look less like exploitation once the user is authenticated. From that point onward, malicious operations can increasingly resemble ordinary administrative activity, making behavioral monitoring much more important than simply watching for exploit signatures.
Talos identified three distinct clusters of post-compromise activity, which dramatically raises the significance of these vulnerabilities. The first cluster, tracked as UAT-12197, exploited CVE-2026-20079 and then placed a JSP-based web shell inside the Cisco Security Manager Tomcat webroot. The attackers subsequently deployed a malicious JAR file that functioned as a command executor and used Cisco FMC’s internal database interfaces to retrieve user authentication information and credentials. This is a classic demonstration of why exploitation of a management platform should immediately be treated as a credential-compromise event rather than simply a server compromise.
A firewall management system naturally possesses information attackers value enormously. It understands the network topology, firewall objects, administrative users, managed devices, internal addresses, VPN relationships and security policy. It may also contain credentials or connectivity required to communicate with managed security devices. Once an attacker obtains root access to the FMC, they are no longer blindly probing the enterprise from the outside. They may be able to study the organization from the same management perspective used by the security team itself.
The second cluster, UAT-11823, is even more concerning because Talos assesses with high confidence that it overlaps in tooling with the Sandworm ecosystem. The actor obtained initial access through CVE-2026-20079 or static credentials associated with CVE-2026-20316, modified a `license.tmp` package to establish a Netcat reverse shell, harvested device configurations, and ultimately deployed a variant of Cyclops Blink. Talos notes that Cyclops Blink has previously been attributed by U.S. and U.K. authorities to the Russian Sandworm APT.
The Cyclops Blink deployment demonstrates why compromise of network security appliances is strategically attractive to advanced actors. The implant provides persistence, DNS-over-HTTPS address resolution, file administration, credential harvesting, arbitrary command execution, network scanning and packet sniffing. Those capabilities are particularly dangerous when placed on a firewall-management system because the compromised device already sits in a trusted administrative position with access to multiple parts of the network.
Packet sniffing alone illustrates the problem. An ordinary compromised endpoint may see only the traffic associated with one user or subnet. A network-management platform may have visibility into infrastructure and administrative communications that can expose credentials, network relationships and security operations. Attackers therefore gain not merely another Linux host but a privileged observation point inside the enterprise.
The third intrusion cluster, UAT-11988, shows that the same FMC weaknesses are useful not only to state-sponsored actors but also to financially motivated ransomware operators. Talos assesses UAT-11988 as a ransomware operator whose behavior was consistent with Qilin affiliates. The attackers used static credentials associated with CVE-2026-20316 to access FMC, then abused legitimate built-in tooling to perform extensive reconnaissance, harvest credentials, enumerate Active Directory information and create a list of endpoints for eventual encryption.
This is particularly important because the threat actor did not need to introduce sophisticated malware immediately. They abused the legitimate `package_info.pl` utility to execute attacker-controlled `license.tmp` packages with root privileges. The same trusted administrative functionality designed to install or inspect legitimate packages became an execution mechanism for malicious commands. This is living-off-the-land activity applied to a security appliance, and it creates the same detection problem defenders face on Windows endpoints: trusted utilities performing technically legitimate actions for malicious purposes.
The reconnaissance conducted from FMC was extensive. Talos observed collection of hostnames, IP addresses, directory listings, Active Directory service-account credentials, MySQL credentials, domain account information, computer objects and mappings covering domain controllers, ADFS servers, Exchange systems, file servers and database servers. This illustrates something fundamental about centralized security management platforms: they can act as a ready-made map of the enterprise.
The attackers then deployed a SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems. Ports associated with LDAP, LDAPS, Kerberos, SMB, RPC and WinRM were forwarded through the compromised FMC environment. At that point the firewall management system effectively became an attacker-controlled gateway into the internal network. The same device administrators trusted to manage perimeter security was being used to bypass that perimeter.
Eventually the operators deployed Impacket, Invoke-TheHash, custom antivirus-killing tools and Qilin ransomware on selected systems. This provides one of the clearest examples of why network appliance vulnerabilities should not be evaluated only according to whether the appliance itself can be disrupted. The ultimate victim may not be the FMC server at all. The compromise can become an intermediate step toward domain-wide ransomware deployment.
The incident therefore reinforces the need to classify firewall managers, SIEM platforms, RMM systems, hypervisor managers and identity servers as Tier-0 or equivalent infrastructure. These systems do not simply run another business application. They control or observe large portions of the environment. Compromise of one administrator workstation may affect that administrator. Compromise of the security-management plane can affect the entire security architecture.
Internet exposure is an obvious priority. Cisco notes that the attack surface for CVE-2026-20079 and CVE-2026-20316 is reduced when the FMC management interface is not publicly accessible. In most organizations, there is little justification for exposing a firewall-management console directly to arbitrary internet sources. Remote administrators should normally access such systems through tightly controlled management networks, VPNs or privileged-access infrastructure.
However, removing public exposure should not be mistaken for complete remediation. Both vulnerabilities remain important internally because an attacker who compromises a VPN account, administrator laptop or another server may then be able to reach FMC. Management interfaces should therefore be restricted to dedicated administrative networks and explicitly authorized hosts rather than merely hidden somewhere behind the perimeter.
Cisco has already released hotfixes and strongly recommends applying them immediately rather than waiting for its broader hardening release. Talos says a comprehensive hardening release combining these fixes with other internally discovered vulnerabilities is planned for the week of September 14. Given the observed exploitation, organizations should not wait for the consolidated release if their current FMC version remains vulnerable.
More importantly, Cisco explicitly warns that the hotfixes prevent future exploitation but may not address an existing compromise. Customers who identify indicators of exploitation are advised to contact Cisco TAC for recovery assistance. That distinction is critical. Installing the patch closes the vulnerability, but it does not remove a web shell, Cyclops Blink implant, malicious SSH configuration, stolen credentials or attacker-created tunnels already established on the system.
Cisco provides a useful compromise check involving FMC logs. Administrators can search for execution of `package_info.pl` against `/var/tmp/license.tmp`; Cisco states that the presence of this activity may indicate exploitation. Organizations should combine that check with review of unexpected JSP files, JAR packages, reverse-shell processes, unusual SSH configuration, unrecognized accounts and suspicious outbound connections.
Externally retained logging becomes particularly important once root access is possible. An attacker with root privileges on FMC may potentially modify or delete evidence stored locally. Administrative, authentication and system logs should therefore be forwarded to independent logging infrastructure whenever possible. Network telemetry should also record connections originating from management systems, because outbound communications from a firewall manager are often much easier to baseline than traffic from ordinary user endpoints.
Credential rotation should also form part of incident response. Talos observed attackers querying FMC databases specifically to harvest user authentication information and credentials. If compromise is confirmed, organizations should assume that credentials stored or accessible through the platform may have been exposed and should review administrative passwords, service accounts and other secrets associated with managed devices.
Configuration integrity deserves equal attention. UAT-11823 harvested managed-device configurations, demonstrating that attackers may obtain detailed firewall policies and topology information even without immediately modifying them. Organizations should maintain known-good backups of firewall and FMC configurations and compare current state against them following suspected compromise.
Administrators should also investigate whether firewall rules, NAT policies, VPN configuration, access-control lists or logging settings changed during the intrusion period. An attacker does not necessarily need to leave malware behind if they can create one permissive firewall rule or hidden management path that provides persistent access later.
Talos has published Snort coverage for both vulnerabilities, including SIDs 66075 through 66080 for CVE-2026-20079 and SID 66883 for CVE-2026-20316, along with additional rules covering observed malware. Network intrusion prevention can therefore provide useful detection and mitigation, but signatures should complement rather than replace patching and forensic investigation. Attackers who already gained access before IPS rules were deployed may no longer need to exploit the original vulnerability.
The contrast between the two CVSS scores also deserves emphasis. CVE-2026-20079 is a straightforward maximum-severity 10.0 vulnerability that immediately attracts attention. CVE-2026-20316 scores only 5.3, yet Talos observed it contributing to intrusions that eventually involved Cyclops Blink and Qilin ransomware. This is exactly why vulnerability prioritization cannot depend solely on severity ratings.
A lower-severity vulnerability becomes highly dangerous when it provides the missing step in an attack chain.
Attackers do not care what score appears beside the CVE.
They care what the vulnerability enables next.
The larger lesson from these Cisco FMC attacks is therefore about management-plane trust.
Organizations invest heavily in firewalls because they expect those systems to control attacker movement.
But the manager controlling those firewalls is itself a high-value target.
Once the attacker compromises the management plane, they can potentially see the network through the defender’s eyes, harvest the defender’s credentials, abuse the defender’s trusted tools and create tunnels through the very infrastructure intended to stop them.
That is why FMC should not merely be patched like another appliance.
It should be protected like the keys to the firewall estate itself.

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
Source: Active exploitation of Cisco Secure Firewall Management Center vulnerabilities via Cisco Talos — published 09 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.