Vulnerabilities

Cisco Confirms Root-Access Flaw Already Exploited by Ransomware and State Hackers

Cisco Confirms Root-Access Flaw Already Exploited by Ransomware and State Hackers

Cisco has confirmed that a maximum-severity flaw in its Secure Firewall Management Center software is being exploited in real attacks and the company’s own threat intelligence unit says at least three separate groups are already inside compromised consoles: a ransomware affiliate, an APT tied to Russia’s Sandworm and a third crew running a web shell for credential theft.

The vulnerability, CVE-2026-20079, carries the maximum CVSS score of 10.0. It lets an unauthenticated attacker send a crafted HTTP request to the FMC web interface and execute commands as root, no credentials required.

Cisco disclosed the flaw in March and said then that it had no evidence of exploitation. That changed this week. “In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,” the company said in an update to its advisory on Wednesday. But the indicator of compromise Cisco published to help customers check for a break-in is dated 23 July, a month before its own stated discovery date. Cisco has not explained the gap.

Cisco credits its own engineer Brandon Sakai, with finding the root-access bug during internal testing. A second Secure FMC flaw surfaced a few months later from outside researchers: CVE-2026-20316, reported by Jimi Sebree of Horizon3.ai and Andy Niu of TrendAI Research, lets an attacker log in with a hardcoded, low-privilege account built into the software.

Its CVSS score is a modest 5.3. Cisco rated it High severity anyway because access from that account can be chained into the root-level bug above. That is exactly what happened.

Talos Has Already Named the Attackers

Cisco Talos, the company’s own threat intelligence arm says it is tracking three distinct clusters of activity inside compromised FMC instances.

The first, tracked as UAT-12197, planted a web shell in the management console’s own web root, then used it to run a small Java-based tool that pulled usernames and password hashes straight out of the FMC database.

The second, UAT-11823, shares tooling with Sandworm, the Russian military intelligence unit the UK and US have publicly linked to the 2015 and 2016 Ukraine power grid attacks. Talos assesses with high confidence that this group chained CVE-2026-20079 with the static-credential bug, then deployed a variant of Cyclops Blink, a modular implant previously attributed to Sandworm that can steal credentials, exfiltrate files and sniff network traffic from inside the compromised device.

The third, UAT-11988, is a Qilin ransomware affiliate. It used the static-credential flaw for initial access, then lived off the FMC’s own built-in tools to map the victim’s Active Directory, tunnel out through the firewall itself and build a target list before deploying Qilin on the endpoints it found.

One Console, Every Firewall Downstream

FMC is not just another server. It is the single console that pushes policy to every Cisco firewall it manages which is why the CVSS vector for CVE-2026-20079 includes a scope change, a successful attacker on the FMC box can reach the firewalls it manages. A compromised management console is a compromised firewall estate.

How many consoles remain reachable from the internet is unclear. VulnCheck counted roughly 300 to 700 internet-facing FMC instances back in March, when the flaw was first disclosed. That was five months and several patch cycles ago and the firm has not published an updated count since. Treat the March figure as a floor, not a current one.

The Hotfix Has Been Out Since July

Cisco released hotfixes for both vulnerabilities on 31 July, more than five weeks before it confirmed exploitation of CVE-2026-20079 specifically. There is no workaround for either flaw. Organisations still running Secure FMC 7.0, 7.2, 7.4, 7.6, 7.7 or 10.0 without the hotfix should apply it now rather than wait for the broader hardening release Cisco says is coming next week.

Check for compromise before patching. In expert mode on the FMC appliance, run zgrep “package_info.*license” /var/log/messages*. If the output references /var/tmp/license.tmp, treat the device as breached, not merely vulnerable: the hotfix stops new intrusions, it does not undo one already under way. Call Cisco TAC before touching anything else on that box.

CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalogue on Wednesday, one of four vulnerabilities added that day. The listing binds only US federal civilian agencies which have until 12 September to secure their systems but it is as close to independent confirmation of active exploitation as this story gets outside Cisco’s own telemetry. For everyone else, the deadline was 31 July, the day the hotfix shipped.

References

  1. Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
  2. Cisco Secure Firewall Management Center Software Static Credential Vulnerability
  3. Active Exploitation of Cisco Secure Firewall Management Center Vulnerabilities
  4. Cisco Confirms CVE-2026-20079 Secure FMC Flaw Exploited in Attacks
  5. CISA Adds Four Known Exploited Vulnerabilities to Catalog
  6. CVE-2026-20079 – Cisco FMC Authentication Bypass RCE Analysis

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.