Cisco Talos has identified active exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. CVE-2026-20079 is a critical authentication bypass with a CVSS score of 10.0, allowing unauthenticated remote attackers to execute scripts and obtain root access. CVE-2026-20316 involves static credentials that can be exploited for low-privileged access and subsequently chained with other vulnerabilities for privilege escalation.
Analysis revealed three distinct threat clusters. UAT-12197 utilized web shells and JAR-based executors for credential theft, while UAT-11823 (linked to the Russian Sandworm APT) deployed the Cyclops Blink modular implant. A third cluster, UAT-11988, involved a Qilin ransomware operator using living-off-the-land techniques and reverse-SSH tunneling to prepare for environment-wide encryption. Organizations are strongly urged to apply Cisco's released hotfixes immediately to mitigate these active threats.
Top comments (0)