by datastudy.nl

Field notes for teams tracking critical CVEs and major incidents

Engineering

Cisco FMC CVE-2026-20079: root access to ransomware

Cisco FMC CVE-2026-20079 lets unauthenticated attackers gain root on firewall managers. Three threat clusters are exploiting it, including Qilin ransomware and suspected Sandworm activity.

Chart showing the CVSS scores of the two exploited Cisco FMC vulnerabilities: CVE-2026-20079 at 10.0 and CVE-2026-20316 at 5.3
CVSS scores of the two exploited Cisco FMC vulnerabilities. Source: Cisco advisory. Data Today benchmark.

A CVSS 10.0 flaw in your firewall manager is a direct path from unauthenticated network access to root. Cisco disclosed that three distinct threat clusters, including a Qilin ransomware affiliate and operators suspected of ties to Russian state-sponsored group Sandworm, are actively exploiting two patched vulnerabilities in Secure Firewall Management Center (FMC) software. The dominant flaw, CVE-2026-20079, is an authentication bypass in the FMC web interface that gives attackers root on the underlying OS. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, giving federal agencies three days to patch. Your window is equally short.

If you run on-premises Cisco FMC, you need to apply hotfixes immediately and triage for compromise.

What exactly are the two exploited Cisco FMC vulnerabilities?

Cisco's advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 covers CVE-2026-20079, scored at CVSS 10.0. The weakness is CWE-288, authentication bypass using an alternate path or channel. An unauthenticated, remote attacker can send crafted HTTP requests to bypass authentication and execute script files on the affected device, obtaining root access to the underlying operating system. The advisory explicitly states there are no workarounds.

The second flaw, CVE-2026-20316, carries a CVSS score of 5.3. This vulnerability stems from static credentials and allows an unauthenticated, remote attacker to log in using a low-privilege account to access sensitive data. It can be paired with other vulnerabilities for privilege escalation.

Bar chart comparing CVSS scores: CVE-2026-20079 at 10.0 and CVE-2026-20316 at 5.3
CVSS scores of the two exploited Cisco FMC vulnerabilities. Source: Cisco Advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. Data Today benchmark.

As the chart above shows, the gap between these two flaws is stark. A 10.0 means a single HTTP request to the FMC web interface yields full root on the box. A 5.3 sounds manageable until you realize it gives an attacker a low-privilege foothold, enough to start reconnaissance, steal credentials, and move laterally using legitimate FMC tooling.

Affected releases include Cisco Secure Firewall Management Center Software 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. The hosted equivalent, Security Cloud Control Firewall Management, is already patched on Cisco's side.

Which threat actors are inside the FMC exploits?

Cisco Talos identified three clusters of post-compromise activity, each using the vulnerabilities differently.

The first cluster, tracked as UAT-12197, exploits CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor. Attackers use this to query internal databases and extract user authentication data and credentials.

The second cluster, UAT-11823, exploits both vulnerabilities and is believed to be the work of Russian state-sponsored group Sandworm. This group delivers a Netcat-based reverse shell, runs two bash scripts to harvest managed-device configurations, and installs a variant of Cyclops Blink, a modular ELF implant previously attributed to Sandworm. Cyclops Blink allows the attackers to harvest credentials, execute commands, perform packet sniffing, and conduct network scanning.

The third cluster, UAT-11988, is a ransomware operation with high confidence attribution to a Qilin affiliate. This group exploits CVE-2026-20316 for initial access using the static credentials, then uses legitimate built-in FMC tooling in a living-off-the-land approach. Their playbook includes extensive reconnaissance of the victim environment, deploying tunneling tools like a Python SOCKS5 proxy and a reverse SSH tunnel to maintain network access, collecting credentials including Active Directory service accounts and MySQL credentials, building a target list of endpoints, terminating security tools, and deploying Qilin ransomware on selected systems.

How does the attack chain work in practice?

The Qilin ransomware cluster demonstrates the most complete kill chain. After logging in with the static credentials from CVE-2026-20316, the attackers don't immediately drop malware. They use the FMC's own built-in tools to conduct network and endpoint reconnaissance, blending into normal administrative traffic.

The stolen information included hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.

The attackers then deployed a Python SOCKS5 proxy and a reverse SSH tunnel to maintain persistent access. These tunnels forwarded traffic for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM. They used post-exploitation tools including Impacket to move laterally before deploying AV killers and delivering the ransomware payload.

This is a living-off-the-land attack where the compromised firewall manager becomes the pivot point into your entire environment. The attacker doesn't need custom malware for the first stages because your FMC gives them the tooling to reconnoiter and steal credentials.

What is the patch and triage timeline?

Cisco first published the advisory for CVE-2026-20079 on March 4, 2026. On September 9, 2026, Cisco issued version 2.5 of that advisory, updating the exploitation status to confirm active exploitation has been observed since August.

CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog on September 9, 2026, with a due date of September 12, 2026. The catalog entry has the forensicTriage field set to Yes, which under BOD 26-04 obliges federal civilian agencies not only to remediate within the window but to carry out a forensic triage of the asset to assess whether it has been compromised.

Cisco ships remediation as a hotfix per train, not a maintenance release. The specific hotfix files are:

  • Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar for 7.0
  • Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar for 7.2
  • Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar for 7.4
  • Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar for 7.6
  • Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar for 7.7
  • Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar for 10.0

Cisco has stated it intends to ship a comprehensive hardening release the week of September 16, 2026, consisting of these hotfixes along with other internally discovered vulnerabilities. But given the in-the-wild abuse, apply the hotfixes now rather than waiting for the hardening bundle.

What should I do if I run Cisco FMC on premises?

Identify every on-premises Secure Firewall Management Center, including standalone virtual appliances and any instance parked in a management VLAN that nobody has looked at since it was built. Apply the hotfix matching your train immediately.

Because the forensicTriage flag is set, patching alone does not discharge your obligation. You need to check for indicators of compromise. Cisco's advisory carries the IOCs and the CLI command added in the July 31 and August 5 revisions. Use that section to run the check.

If the check comes back positive, contact Cisco TAC. Do not reimage the box. A reimage destroys forensic evidence that determines whether the attacker moved laterally, what credentials they stole, and whether your broader environment is compromised.

Here is the triage priority list:

  • Patch every FMC instance in versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 with the matching hotfix
  • Run the IOC check using the CLI commands from the advisory revisions dated July 31 and August 5
  • Rotate credentials for any account that the FMC manages, including Active Directory service accounts, MySQL credentials, and domain admin credentials
  • Audit network segmentation between the FMC management VLAN and your production environment, because the Qilin cluster used FMC tooling to conduct reconnaissance and pivot
  • Contact Cisco TAC if the IOC check returns positive, rather than reimaging over the evidence

For broader context on how CISA's Known Exploited Vulnerabilities catalog drives patch timelines and what it means for your edge gear, see our earlier analysis of edge device patch clocks.

The clock is already running

The most dangerous detail in this story is timing. Cisco says exploitation began in August. A public proof-of-concept dated August 20 means an unpatched manager exposed to the network has been reachable by a known-good exploit for weeks. CISA's three-day deadline is a federal mandate, but the attacker's timeline started a month ago. Every day an FMC instance sits unpatched is a day an attacker could be using your firewall manager to map your network, harvest your credentials, and stage a ransomware deployment.

Sources