www.securityweek.com 10 Sept 2026, 10:06 UTC

Cisco Firewall Flaw Exploited by Sandworm and Qilin Ransomware

Cisco Firewall Flaw Exploited by Sandworm and Qilin Ransomware
CyberSIXT Evidence Panel

CISCO and the US Cybersecurity and Infrastructure Security Agency (CISA) have warned that CVE-2026-20079, a critical authentication bypass flaw in Cisco Secure Firewall Management Center (FMC), has been exploited in the wild. Disclosed earlier in 2026, the vulnerability allows a remote, unauthenticated attacker to run malicious scripts on affected devices and obtain root access to the underlying operating system by sending crafted HTTP requests to the FMC.

Cisco released patches in early March and, by late July, added indicators of compromise to its advisory; on 9 September the company disclosed active exploitation had been observed in August. CISA subsequently added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue, with federal agencies instructed to remediate by 12 September.

SecurityWeek’s coverage notes three active exploitation clusters targeting CVE-2026-20079 alongside CVE-2026-20316, identified by Cisco Talos. The cluster UAT-12197 deployed a web shell to deliver a malicious JAR and harvest authentication data. A separate cluster, UAT-11823, is linked to the Russian APT Sandworm and used the FMC flaws to deploy Cyclops Blink malware, enabling file transfer, credential harvesting, arbitrary command execution and network scanning.

The third cluster, UAT-11988, is tied to the Qilin ransomware and leveraged CVE-20316 to gain FMC access, perform reconnaissance, steal credentials and enumerate endpoints for encryption. Cisco advises FMC users to apply patches and to limit FMC interface exposure to the internet to reduce risk.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline