CISCO Talos researchers say two critical flaws in Cisco Secure Firewall Management Center (FMC) are being actively exploited in the wild. The vulnerabilities are CVE-2026-20079, an authentication bypass in the FMC web interface, and CVE-2026-20316, a flaw involving hardcoded static credentials. Exploitation chains first gain unauthenticated access via the bypass, then use the static credential to establish initial access and escalate to full control. Cisco notes on-prem FMC versions 7.0 through 7.7 are affected; cloud-delivered FMC and standalone ASA devices are not impacted by these attack vectors.
In observed campaigns, attackers deploy post‑compromise tools after obtaining root on the FMC host. One cluster (UAT-12197) used a JSP-based web shell to query internal databases for authentication data. Another cluster (UAT-11823) deployed Cyclops Blink via proxy tooling and reverse shells to enable packet sniffing and DNS over HTTPS. A third cluster (UAT-11988) set up a Python SOCKS5 proxy and a reverse‑SSH tunnel to forward LDAP, SMB and Kerberos traffic back to attacker infrastructure.
The result is broad access to management policies and saved credentials, effectively giving attackers control over the security posture of affected networks.
Cisco has issued hotfixes for all affected FMC versions and warns there are no official workarounds to the authentication bypass. Administrators should apply the security advisories for authentication bypass and static credentials immediately, and, while patches are pending, restrict access to FMC management interfaces via ACLs and VPNs.