Cisco FMC vulnerabilities are being actively exploited against unpatched firewall management systems. Cisco Talos disclosed the attacks on 9 September 2026, warning that state-sponsored and criminal operators have used the flaws to gain access, deploy malware and prepare ransomware operations.
The activity centres on two vulnerabilities in Cisco Secure Firewall Management Center Software: CVE-2026-20079 and CVE-2026-20316. Cisco has released hotfixes for affected software and is urging organisations to apply them immediately.
Cisco FMC vulnerabilities exploited in the wild
The most serious flaw, CVE-2026-20079, is an authentication bypass vulnerability with the maximum CVSS severity score of 10.0. It allows an unauthenticated remote attacker to bypass authentication controls and execute scripts on an affected Cisco Secure FMC device.
Successful exploitation provides root access to the underlying operating system. This level of access gives an attacker extensive control over the management appliance and creates opportunities to steal credentials, install persistent access tools and inspect the networks managed through FMC.
The second vulnerability, CVE-2026-20316, has a CVSS score of 5.3. It involves static credentials that can allow a remote attacker to sign in using a low-privileged account. Although its standalone severity is lower, Talos warns that it can be combined with other Cisco FMC vulnerabilities to elevate privileges and support a broader compromise.
Talos has confirmed in-the-wild abuse of both flaws. Its investigation identified three separate clusters of post-compromise activity involving state-sponsored actors, crimeware operators and an actor assessed with high confidence to be a ransomware operator.
How the Cisco Secure FMC attacks work
CVE-2026-20079 removes a critical security boundary by enabling access without valid authentication. An attacker who can remotely reach a vulnerable FMC instance can execute scripts and obtain root privileges without first compromising a legitimate user account.
CVE-2026-20316 provides another route into the system through static credentials. The resulting account is low privileged, but attackers can combine this access with additional vulnerabilities or legitimate FMC functions to extend their control.
The observed intrusions show that exploitation is not limited to initial access. Attackers have used compromised systems to establish command channels, conduct reconnaissance, extract credentials and maintain connectivity into victim networks. In one case, the activity progressed towards identifying endpoints for encryption or locking.
Because FMC centrally manages Cisco Secure Firewall deployments, a compromised instance may also provide valuable information about network architecture, security policies and connected systems. Talos observed attackers abusing both malicious tools and legitimate built-in capabilities after gaining access.
Three attack clusters identified by Cisco Talos
Talos separated the ongoing exploitation into three clusters based on the infrastructure, tooling and techniques observed. The clusters demonstrate that the Cisco FMC vulnerabilities are attracting more than one category of threat actor.
UAT-12197 deployed web shells and stole credentials
The first cluster, tracked as UAT-12197, exploited CVE-2026-20079. After obtaining access, the attackers deployed web shells that could provide persistent remote control through a web-facing interface.
The group also installed a Java Archive, or JAR, based command executor. Talos observed credential exfiltration alongside these tools, indicating that the attackers sought information that could support continued access or movement beyond the compromised FMC appliance.
UAT-11823 delivered Cyclops Blink malware
The second cluster, UAT-11823, used both CVE-2026-20079 and CVE-2026-20316. The attackers deployed a Netcat-based reverse shell, allowing the compromised system to initiate a command connection back to attacker-controlled infrastructure.
They also installed proxy tooling before deploying a variant of Cyclops Blink malware. The United States and United Kingdom have previously attributed Cyclops Blink to Sandworm, a Russian advanced persistent threat group. Talos therefore associates this cluster with state-sponsored activity, although the report uses the UAT-11823 tracking name for the observed intrusion set.
UAT-11988 prepared a ransomware operation
Talos assesses with high confidence that the third cluster, UAT-11988, is a ransomware operator. In this intrusion, the attacker initially accessed the system using the static credentials associated with CVE-2026-20316.
Rather than relying entirely on custom malware, the operator abused legitimate built-in FMC tooling in a living-off-the-land approach. This can make activity harder to distinguish from normal administration because trusted system functions are used to perform malicious tasks.
Talos observed the actor conducting extensive reconnaissance across the victim environment. The attacker also deployed tunnelling tools to maintain network access, harvested credentials and assembled a list of endpoints that could be encrypted or locked during a later ransomware stage.
Patch status and affected Cisco products
The disclosure applies to affected and unpatched instances of Cisco Secure Firewall Management Center Software. The Talos report does not list individual vulnerable version branches, so administrators should use Cisco’s advisories for CVE-2026-20079 and CVE-2026-20316 to match deployed releases against the affected-version tables and available fixes.
Hotfixes for affected software versions had already been released when Talos published its warning on 9 September 2026. Cisco also plans a comprehensive hardening release during the week beginning 14 September 2026. That release is expected to combine the two hotfixes with fixes for other internally discovered vulnerabilities.
The Cisco FMC vulnerabilities remain under active exploitation, meaning organisations should not wait for the broader hardening release if a compatible hotfix is already available. Cisco and Talos both recommend applying the current security updates immediately.
What organisations should do now
Organisations operating Cisco Secure FMC should prioritise actions directly related to this campaign:
- Identify all deployed FMC instances and confirm their exact software releases.
- Check those releases against both Cisco security advisories and apply the relevant hotfixes.
- Review systems for unexpected web shells, JAR files, Netcat activity, proxy tools and network tunnels.
- Investigate unusual use of built-in FMC tools, particularly reconnaissance and credential-access activity.
- Reset potentially exposed credentials if evidence suggests that an appliance was compromised.
Root access, credential theft and observed ransomware preparation make retrospective investigation important, even after patching. Applying a fix prevents future exploitation of the vulnerabilities, but it does not remove persistence or tools installed during an earlier compromise.
Originally reported by blog.talosintelligence.com.







