A critical Cisco Secure Firewall Management Center vulnerability is under active exploitation by state-sponsored cyber espionage operators and financial extortionists. Cisco Talos confirmed that threat actors—including the Russian state-sponsored group Sandworm and affiliates operating the Qilin ransomware payload—are actively abusing CVE-2026-20079 alongside CVE-2026-20316 to gain root access to management infrastructure, steal network credentials, and breach managed firewall environments.
Flaw Mechanics: Root Access and Static Accounts
The most severe flaw under active attack is CVE-2026-20079, a critical authentication bypass vulnerability (CWE-288) discovered during internal security testing by Cisco’s Brandon Sakai. The bug stems from an improper system process created during the FMC appliance boot sequence. Remote, unauthenticated attackers can exploit the vulnerability simply by sending specially crafted HTTP requests to an unpatched management interface, allowing them to execute scripts and system commands with root privileges.
The flaw carries a maximum CVSS v3.1 score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope changed metric (S:C) highlights the underlying architectural risk: compromising the centralized management platform directly compromises the security perimeter of every downstream network device managed by the software.
The second exploited flaw, CVE-2026-20316, was reported by Jimi Sebree of Horizon3.ai and disclosed with patches on July 29, 2026. It involves static, hard-coded credentials assigned to a low-privileged default account embedded in FMC software. While granting lower privilege initially, it allows unauthenticated remote adversaries to log directly into vulnerable instances to initiate post-exploitation activities.
Three Distinct Intrusion Clusters in the Wild
Cisco Talos threat intelligence analysts confirmed that adversaries are actively abusing these vulnerabilities across three distinct operational tracks:
- CSM Tomcat Web Shell Injection: Attackers abusing CVE-2026-20079 drop a malicious web shell into the CSM Tomcat webroot directory. This shell is then used to deploy a secondary malicious Java Archive (JAR) file within the same webroot, providing persistent command execution used to extract user authentication data and harvest memory credentials.
- Sandworm Configuration Harvesting: Russian state-sponsored threat group Sandworm establishes initial access via either flaw before modifying the platform’s
license.tmpfile. The malicious file initiates a reverse shell back to Sandworm command-and-control (C2) servers. Once established, the actors systematically harvest configuration files for all managed Cisco firewalls and deploy a custom implant capable of packet sniffing, network scanning, credential theft, and arbitrary command execution. - Qilin Ransomware Deployment: Operators linked to the Qilin ransomware family leverage CVE-2026-20316 to authenticate directly using the hard-coded account credentials. From there, attackers execute internal host and network reconnaissance, steal domain credentials, deploy utility tools to kill endpoint protection software, and systematically deliver ransomware payloads across enterprise endpoints.
Threat Metrics and Blast Radius
Centralized management platforms represent single points of failure for enterprise network security. Because Cisco Secure Firewall Management Center handles central policy enforcement, access logging, and configuration management across multiple Cisco Secure Firewall devices, compromising FMC grants threat actors a direct path to map internal networks, bypass boundary filtering, and extract VPN credentials without triggering traditional alerts on edge appliances.
Current threat metrics underscore the severity of the campaign: CVE-2026-20079 currently holds an Exploit Prediction Scoring System (EPSS) probability score of 74.7%, placing it in the 99.5th percentile of all tracked software flaws. Combined with confirmed wild exploitation by tier-one APT groups and extortionists, unpatched management instances represent an immediate, critical liability.
According to NVD analyses, affected software releases include Cisco FMC versions 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, and 7.0.2.1.
Action Required: Patching and Interface Hardening
Because active intrusion activity is ongoing, organizations utilizing affected FMC instances should execute the following mitigation steps immediately:
- Apply Hotfixes: Cisco has released software hotfixes for CVE-2026-20079 and CVE-2026-20316 across affected branches. Security teams must apply these targeted hotfixes immediately rather than waiting for Cisco’s comprehensive hardening release scheduled for the week of September 16, 2026.
- Isolate FMC Interfaces: If hotfixes cannot be immediately applied, restrict access to the FMC management interface. Ensure HTTP and HTTPS management ports are disconnected from the public internet and restricted solely to secure, out-of-band management subnets or dedicated administrative jump boxes.
- Hunt for Indicators of Compromise: Security operations teams should inspect the CSM Tomcat webroot directory for unauthorized
.jspor.jarfiles, verify the integrity of the systemlicense.tmpfile, and audit authentication logs for unusual activity originating from default low-privilege accounts or unexpected root process execution.
Related content
Cisco Secure Firewall Management Center Bugs Exploited in the Wild (CVE-2026-20079)
AdvisoryCisco FMC Authentication Bypass (CVE-2026-20079) Grants Root Access
AdvisoryCisco FMC Hard-Coded Password Flaw (CVE-2026-20316): Attack Paths & Triage
Security NewsCisco Secure FMC Zero-Day Exploited via Static Credentials (CVE-2026-20316)
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call