Cisco Secure FMC CVE-2026-20079 exploited; Talos: Qilin + Sandworm-linked clusters
Cisco PSIRT advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 covers CVE-2026-20079, a maximum-severity (CVSS 10.0) authentication-bypass in Cisco Secure Firewall Management Center (FMC) and related management paths. Improper process creation at boot lets an unauthenticated remote attacker send crafted HTTP requests to the web interface and execute scripts/commands as root. Cisco updated the advisory on 9 September 2026 to state PSIRT became aware of active exploitation in August 2026 (no public attribution or start date). Cloud-hosted Security Cloud Control is already patched per Cisco; on-prem FMC has no workaround — upgrade to a fixed release. BleepingComputer (9 Sep) notes CISA added CVE-2026-20079 to the KEV catalog with FCEB remediation due 12 September 2026. Hunt guidance from related July FMC coverage includes /var/log/messages activity around /var/tmp/license.tmp. Distinct from desk cards cisco-esa-iosxr-20260902 and cisco-sd-wan-2026. Primary: Cisco PSIRT; wire: BleepingComputer. NEW 10 September 2026 (Cisco Talos “Active exploitation of Cisco Secure Firewall Management Center vulnerabilities”; BleepingComputer same day): Talos tracks three post-compromise clusters on FMC — UAT-11988 (high confidence Qilin ransomware affiliates), UAT-11823 (high confidence APT tooling overlap with Sandworm / Cyclops Blink deployment), and UAT-12197 (state-sponsored/crimeware mix). Actors abused CVE-2026-20079 and companion CVE-2026-20316 (static low-privileged credentials; CVSS 5.3 per wire, Cisco High because it chains with other FMC bugs) to plant web shells, steal AD/MySQL credentials, stand up SOCKS5/SSH tunnels, and in one cluster deploy Qilin ransomware. Install Cisco hotfixes for both CVEs immediately; comprehensive hardening package noted as forthcoming. Distinct companion CVE covered here rather than a sibling card.
- Product
- Cisco Secure Firewall Management Center (FMC) / Security Cloud Control Firewall Management
- Versions
- See Cisco advisory for fixed FMC releases; cloud Security Cloud Control already patched per Cisco
- CVSS
- 10.0
- Exploited in Australia?
- unknown
- Patch to
- Upgrade FMC to a fixed release per Cisco PSIRT; no workaround; hunt /var/tmp/license.tmp-related messages
Primary: Cisco PSIRT — Secure FMC auth bypass CVE-2026-20079 · Vendor: Cisco PSIRT · CVE: CVE-2026-20079, CVE-2026-20316 · Cisco Talos — FMC ongoing exploitation (10 Sep 2026); BC same day
