>samit_hota
Back to security news

Security News · SN-2026-466

CRITICALCVE-2026-20079OPEN

Cisco FMC Vulnerabilities Under Active Attack by Sandworm and Ransomware Gangs

Affected: Cisco Secure Firewall Management Center (7.0.0 · 7.0.0.1 · 7.0.1 · 7.0.1.1 · 7.0.2 · 7.0.2.1)

Samit Hota·
#news#ransomware#cisco

A critical Cisco Secure Firewall Management Center vulnerability is under active exploitation by state-sponsored cyber espionage operators and financial extortionists. Cisco Talos confirmed that threat actors—including the Russian state-sponsored group Sandworm and affiliates operating the Qilin ransomware payload—are actively abusing CVE-2026-20079 alongside CVE-2026-20316 to gain root access to management infrastructure, steal network credentials, and breach managed firewall environments.

Flaw Mechanics: Root Access and Static Accounts

The most severe flaw under active attack is CVE-2026-20079, a critical authentication bypass vulnerability (CWE-288) discovered during internal security testing by Cisco’s Brandon Sakai. The bug stems from an improper system process created during the FMC appliance boot sequence. Remote, unauthenticated attackers can exploit the vulnerability simply by sending specially crafted HTTP requests to an unpatched management interface, allowing them to execute scripts and system commands with root privileges.

The flaw carries a maximum CVSS v3.1 score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope changed metric (S:C) highlights the underlying architectural risk: compromising the centralized management platform directly compromises the security perimeter of every downstream network device managed by the software.

The second exploited flaw, CVE-2026-20316, was reported by Jimi Sebree of Horizon3.ai and disclosed with patches on July 29, 2026. It involves static, hard-coded credentials assigned to a low-privileged default account embedded in FMC software. While granting lower privilege initially, it allows unauthenticated remote adversaries to log directly into vulnerable instances to initiate post-exploitation activities.

Three Distinct Intrusion Clusters in the Wild

Cisco Talos threat intelligence analysts confirmed that adversaries are actively abusing these vulnerabilities across three distinct operational tracks:

  1. CSM Tomcat Web Shell Injection: Attackers abusing CVE-2026-20079 drop a malicious web shell into the CSM Tomcat webroot directory. This shell is then used to deploy a secondary malicious Java Archive (JAR) file within the same webroot, providing persistent command execution used to extract user authentication data and harvest memory credentials.
  2. Sandworm Configuration Harvesting: Russian state-sponsored threat group Sandworm establishes initial access via either flaw before modifying the platform’s license.tmp file. The malicious file initiates a reverse shell back to Sandworm command-and-control (C2) servers. Once established, the actors systematically harvest configuration files for all managed Cisco firewalls and deploy a custom implant capable of packet sniffing, network scanning, credential theft, and arbitrary command execution.
  3. Qilin Ransomware Deployment: Operators linked to the Qilin ransomware family leverage CVE-2026-20316 to authenticate directly using the hard-coded account credentials. From there, attackers execute internal host and network reconnaissance, steal domain credentials, deploy utility tools to kill endpoint protection software, and systematically deliver ransomware payloads across enterprise endpoints.

Threat Metrics and Blast Radius

Centralized management platforms represent single points of failure for enterprise network security. Because Cisco Secure Firewall Management Center handles central policy enforcement, access logging, and configuration management across multiple Cisco Secure Firewall devices, compromising FMC grants threat actors a direct path to map internal networks, bypass boundary filtering, and extract VPN credentials without triggering traditional alerts on edge appliances.

Current threat metrics underscore the severity of the campaign: CVE-2026-20079 currently holds an Exploit Prediction Scoring System (EPSS) probability score of 74.7%, placing it in the 99.5th percentile of all tracked software flaws. Combined with confirmed wild exploitation by tier-one APT groups and extortionists, unpatched management instances represent an immediate, critical liability.

According to NVD analyses, affected software releases include Cisco FMC versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, and 7.0.2.1.

Action Required: Patching and Interface Hardening

Because active intrusion activity is ongoing, organizations utilizing affected FMC instances should execute the following mitigation steps immediately:

  • Apply Hotfixes: Cisco has released software hotfixes for CVE-2026-20079 and CVE-2026-20316 across affected branches. Security teams must apply these targeted hotfixes immediately rather than waiting for Cisco’s comprehensive hardening release scheduled for the week of September 16, 2026.
  • Isolate FMC Interfaces: If hotfixes cannot be immediately applied, restrict access to the FMC management interface. Ensure HTTP and HTTPS management ports are disconnected from the public internet and restricted solely to secure, out-of-band management subnets or dedicated administrative jump boxes.
  • Hunt for Indicators of Compromise: Security operations teams should inspect the CSM Tomcat webroot directory for unauthorized .jsp or .jar files, verify the integrity of the system license.tmp file, and audit authentication logs for unusual activity originating from default low-privilege accounts or unexpected root process execution.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call