Skip to content
Threat Feed
critical threat exploited updated

Active Exploitation of Cisco Secure Firewall Management Center

Multiple threat actors, including state-sponsored groups and ransomware operators, are actively exploiting authentication bypass (CVE-2026-20079) and static credential (CVE-2026-20316) vulnerabilities in Cisco Secure Firewall Management Center to achieve root-level code execution and deploy malware.

CVE search metadata

CVE search record: CVE-2026-20079. Severity: critical. CVSS: 10.0. EPSS: 35.95%. KEV: no. Product: Secure Firewall Management Center, Secure Firewall Threat Defense. Brief: Active Exploitation of Cisco Secure Firewall Management Center. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-fmc-exploitation/

CVE search record: CVE-2026-20316. Severity: medium. CVSS: 5.3. EPSS: 9.82%. KEV: no. Product: Secure Firewall Management Center, Secure Firewall Threat Defense. Brief: Active Exploitation of Cisco Secure Firewall Management Center. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-fmc-exploitation/

What's new

  • 1. new product Sep 10, 12:55 via bsi

Cisco Talos is actively tracking the exploitation of multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) software. Threat actors are chaining CVE-2026-20079, a critical (CVSS 10.0) authentication bypass vulnerability, and CVE-2026-20316, which involves static credentials, to gain initial access and perform lateral movement. Talos has identified three distinct clusters of malicious activity. Cluster UAT-12197 utilizes CVE-2026-20079 to deploy JSP web shells and custom Java-based command executors for credential exfiltration. Cluster UAT-11823, identified as an APT with ties to Sandworm, uses these vulnerabilities to deploy Cyclops Blink malware via a malicious Makeself package. Cluster UAT-11988, assessed as a Qilin ransomware operator, uses static credentials for initial access followed by living-off-the-land (LOTL) techniques to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Defenders must prioritize patching these vulnerabilities, as multiple groups are currently exploiting these flaws in the wild.

Attack Chain

  1. Initial Access: Attackers bypass authentication via CVE-2026-20079 or utilize static credentials (CVE-2026-20316) to access the FMC appliance.
  2. Persistence: Attackers place malicious JSP web shells in the CSM Tomcat webroot directory or modify system startup scripts (e.g., /etc/init.d/) to maintain access.
  3. Execution: Attackers abuse the legitimate package_info.pl utility to execute malicious files (e.g., license.tmp) or custom JAR files (e.g., cmd.jar) with root privileges.
  4. Privilege Escalation: Exploitation of system utilities allows actors to transition from initial low-privileged access to root-level command execution on the underlying OS.
  5. Discovery: Attackers perform system and network reconnaissance, including directory listing, credential harvesting via OmniQuery.pl, and internal database queries.
  6. Command and Control: Deployment of Netcat-based reverse shells and SOCKS proxy/reverse-SSH tunneling tools to maintain communication with actor infrastructure.
  7. Impact: Final stages include exfiltration of configurations, deployment of modular implants like Cyclops Blink, or deployment of Qilin ransomware to target endpoints.

Impact

Successful exploitation allows unauthenticated remote attackers to gain full administrative control over the FMC appliance. Observed impacts include the exfiltration of sensitive configuration data, deployment of modular botnet malware, and large-scale ransomware encryption of downstream enterprise networks.

Recommendation

  1. Apply the security patches provided by Cisco for CVE-2026-20079 and CVE-2026-20316 immediately.
  2. Implement monitoring for unauthorized files in the CSM Tomcat webroot directory.
  3. Audit the use of system-level utilities like package_info.pl and OmniQuery.pl for anomalous command-line arguments.
  4. Block communication with the known C2 IP 208.123.119.215 at the network perimeter.
  5. Monitor for processes spawning unexpected shells or network utilities such as nc (Netcat).

Immediate actions

Patch Cisco FMC instances to the latest version to address CVE-2026-20079 and CVE-2026-20316

IT Operations 24h

Block IP 208.123.119.215 on egress firewalls

SOC 2h

Threat Hunt

Search for files in CSM Tomcat webroot not matching expected deployment hashes

T1505.003 high high confidence hunt now

Data: File integrity monitoring logs

Mitigations

Apply Cisco hotfixes for CVE-2026-20079 and CVE-2026-20316

immediate IT Operations

CVE-2026-20079, CVE-2026-20316

Indicators of compromise

1

ip

TypeValue
ip208.123.119.215