Key Facts
Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) Software. Talos says CVE-2026-20079 is a CVSS 10.0 authentication bypass that can let an unauthenticated remote attacker execute scripts and obtain root access.
Technical Details
Talos describes post-compromise clusters involving web shells, a JAR-based command executor, credential theft, reverse shells, proxy tooling, and use of built-in FMC tooling. It assesses one cluster as a ransomware operator with high confidence and reports another overlaps in tooling with Sandworm.
Impact & Mitigation
Apply Cisco’s released hotfixes for both vulnerabilities immediately and follow the vendor advisory guidance. Talos says a comprehensive hardening release is planned for the week of September 14; affected organizations should also review FMC systems for the indicators and post-compromise activity in its report.
Sources
- Cisco Talos: active FMC exploitation
- Cisco advisory for CVE-2026-20079
- Cisco advisory for CVE-2026-20316
