DEV Community

Mark0
Mark0

Posted on

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos has identified active exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. CVE-2026-20079 is a critical authentication bypass with a CVSS score of 10.0, allowing unauthenticated remote attackers to execute scripts and obtain root access. CVE-2026-20316 involves static credentials that can be exploited for low-privileged access and subsequently chained with other vulnerabilities for privilege escalation.

Analysis revealed three distinct threat clusters. UAT-12197 utilized web shells and JAR-based executors for credential theft, while UAT-11823 (linked to the Russian Sandworm APT) deployed the Cyclops Blink modular implant. A third cluster, UAT-11988, involved a Qilin ransomware operator using living-off-the-land techniques and reverse-SSH tunneling to prepare for environment-wide encryption. Organizations are strongly urged to apply Cisco's released hotfixes immediately to mitigate these active threats.


Read Full Article

Top comments (0)