Summary
Cisco and CISA have confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Cisco Secure Firewall Management Center, is being actively exploited by three distinct threat clusters simultaneously: a credential-theft cluster designated UAT-12197, a group attributed to Russian state-sponsored actor Sandworm operating as UAT-11823, and a Qilin ransomware affiliate designated UAT-11988. CVE-2026-20079 allows an unauthenticated remote attacker to execute scripts as root on affected FMC devices by sending specially crafted HTTP requests. A second vulnerability, CVE-2026-20316, provides low-privileged access via static hard-coded credentials and is being exploited alongside it. CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog and requires federal agencies to remediate by September 12, 2026. Between 300 and 700 internet-exposed FMC instances remain reachable according to Censys and FOFA scanning.
Timeline
| Date | Event |
|---|---|
| March 2026 | Cisco patches CVE-2026-20079; no exploitation confirmed at time of patch |
| Late July 2026 | Cisco updates advisory with indicators of compromise; still no explicit exploitation warning |
| August 2026 | Active exploitation begins; three threat clusters identified by Cisco Talos |
| Sep 9, 2026 | Cisco updates advisory confirming active exploitation since August; CISA adds CVE-2026-20079 to KEV catalog |
| Sep 10, 2026 | Cisco Talos publishes full three-cluster report; federal agency remediation deadline set September 12 |
What Happened
CVE-2026-20079 exists because Cisco Secure FMC creates an improperly configured system process at boot time. An unauthenticated attacker can bypass authentication entirely and execute scripts as root by sending crafted HTTP requests, giving full control of the underlying operating system.
UAT-12197 deployed a JSP web shell into the Cisco Security Manager Tomcat webroot, installed a malicious JAR file named cmd.jar to execute commands, query internal databases, and exfiltrate user credentials. UAT-11823, attributed to Sandworm, modified the license.tmp file to establish a Netcat reverse shell to command-and-control infrastructure, deployed Cyclops Blink malware, and stole firewall configuration data. UAT-11988, the Qilin affiliate, logged in via CVE-2026-20316 static credentials, conducted Active Directory reconnaissance collecting hostnames, IP addresses, domain accounts, and MySQL credentials, staged exfiltrated data in publicly accessible files on the compromised FMC server, then deployed AV killers and Qilin ransomware.
Cisco has released hotfixes for both vulnerabilities and advises restricting internet access to the FMC interface as additional mitigation.
Domain Intelligence
cisco.com — 61.91
Score sits in the low-trust range. Cisco is the vendor of the affected product and the party that both patched the vulnerabilities and published the Talos threat intelligence report. One threat intelligence source has flagged cisco.com but the observation has not been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.
The Trust Observatory · thetrustobservatory.com · September 10, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026