Cisco Firewall Management Software Under Active Attack: Patch Now
Cisco Talos has identified real-world attacks exploiting two vulnerabilities in Cisco's Secure Firewall Management Center (FMC) Software. The more serious flaw, CVE-2026-20079, has a maximum severity score of 10.0 and lets an unauthenticated attacker bypass login controls, run scripts, and gain root access to the underlying system. A second flaw, CVE-2026-20316, scores lower at 5.3 but allows attackers to log in with a low-privileged account, and can be combined with other weaknesses to gain deeper access.
Talos has observed these vulnerabilities being used by multiple threat groups, including state-sponsored and financially motivated actors. In one case, attackers deployed web shells, a tool for executing commands, and stole credentials. In another, attackers used the flaws to install remote access tools and ultimately deployed a variant of Cyclops Blink, malware previously linked to the Russian state-backed group Sandworm.
Cisco has already released hotfixes for both vulnerabilities and is preparing a broader hardening update, expected the week of September 14th, that will address these issues along with other internally found flaws. Organisations running Secure FMC Software should treat this as urgent, given confirmed exploitation in the wild.