Cisco Secure FMC Vulnerability Exploited: Urgent Warning for Organizations

www.news4hackers.com-cisco-secure-fmc-vulnerability-exploited-urgent-warning-for-organizations-cisco-secure-fmc-vulnerability-exploited-urgent-warning-for-organizations

Organizations are warned of the exploitation of a critical vulnerability in Cisco Secure FMC, with CISA adding it to the KEV catalog.

Vulnerability Details

Cisco and the cybersecurity agency CISA issued a warning on Wednesday regarding the exploitation of a critical vulnerability in the Cisco Secure Firewall Management Center (FMC). The flaw, designated CVE-2026-20079, allows a remote, unauthenticated attacker to bypass authentication mechanisms and execute malicious scripts on affected devices, granting root access to the underlying operating system.

CVE-2026-20079 Overview

The vulnerability arises from an improperly configured system process initiated during device boot. Attackers can exploit it by transmitting specially crafted HTTP requests to vulnerable systems, according to Cisco’s advisory.

Patch and Advisory Updates

The vendor addressed the issue in early March with a patch, later updating its advisory in late July to include indicators of compromise (IoCs). At the time, no explicit confirmation of active exploitation was provided. However, Cisco revised its advisory on September 9, stating that it had identified evidence of the vulnerability being actively exploited in August.

CISA’s Response

CISA has since included CVE-2026-20079 in its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to remediate the issue by September 12.

Mitigation Steps

To mitigate risks, Cisco FMC users are advised to apply the available patches and restrict direct internet access to the FMC interface. CVE-2026-20079 marks the third FMC-related vulnerability added to CISA’s KEV list in 2026, following CVE-2026-20316 and CVE-2026-20131, which were previously exploited as zero-day flaws.

Threat Intelligence Findings

Threat intelligence firm Talos has identified three distinct activity clusters leveraging CVE-2026-20079 and CVE-2026-20316.

According to Cisco’s advisory, attackers can exploit the vulnerability by transmitting specially crafted HTTP requests to vulnerable systems.

Cluster Activity Overview

One group, designated UAT-12197, exploited CVE-2026-20079 to deploy a web shell, which facilitated the delivery of a malicious JAR file. This payload enabled attackers to extract user authentication data and credentials from compromised systems. A second cluster, UAT-11823, is linked to the Russian state-sponsored APT group Sandworm. This actor exploited both vulnerabilities to deploy the Cyclops Blink malware, which provides operators with remote control capabilities. A third cluster, UAT-11988, is associated with the Qilin ransomware group. This threat actor used CVE-2026-20316 to infiltrate FMC devices, conduct reconnaissance, steal credentials, and compile a list of endpoints for potential encryption.

Conclusion

Organizations are urged to prioritize patching and implement network segmentation to reduce exposure to such threats. The ongoing exploitation of these vulnerabilities underscores the importance of proactive security measures and continuous monitoring for signs of compromise.


Blog Image

About Author

en_USEnglish