Cisco Discloses Active Exploitation of Critical Firewall Management Center Auth Bypass
Cisco Talos confirmed the active, in-the-wild exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) software: CVE-2026-20079, a maximum-severity (CVSS 10.0) authentication bypass, and CVE-2026-20316 (CVSS 5.3), a static-credential flaw. Threat intelligence researchers identified three distinct intrusion clusters abusing these vulnerabilities. These include campaign UAT-12197 deploying JSP-based web shells and JAR command executors to harvest administrative credentials, UAT-11823 utilizing reverse shells to install variants of the Cyclops Blink modular ELF implant (historically tied to the Sandworm group), and UAT-11988 leveraging built-in FMC tooling in a living-off-the-land pattern to stage Qilin ransomware deployments. Following the findings, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog.
The compromise of a centralized firewall management console represents a catastrophic single point of failure in enterprise network defense. FMC appliances hold the crown jewels of network topology: security policies, VPN configurations, and orchestration credentials across thousands of downstream Firewall Threat Defense (FTD) and ASA devices. Achieving unauthenticated root execution on the management tier enables adversaries to bypass perimeter enforcement, manipulate access control lists, sniff internal traffic, and establish deep persistence without triggering endpoint security agents on host workloads. Network architects and operations teams managing on-premises FMC appliances are immediately exposed if management ports face external or semi-trusted network segments.
This development continues a pervasive industry trend where sophisticated adversaries bypass hardened host endpoints entirely to focus on unmonitored edge appliances and central management controllers. Over recent years, network infrastructure—including VPN gateways, SD-WAN controllers, and unified threat management interfaces—has emerged as the premier entry vector for both state-backed espionage and ransomware cartels. Because network management appliances often lack standard endpoint detection and response (EDR) agent coverage and operate on specialized embedded OS environments, intrusions can dwell undetected for extended durations while attackers harvest credentials to compromise the wider IT and cloud infrastructure.
Practitioners cannot treat this simply as a routine patch cycle; because exploitation began weeks before public alerts, security teams must assume potential compromise. Organizations running on-premises Secure FMC must immediately apply Cisco's hotfixes and evaluate management plane exposure. FMC interfaces should never be exposed to public networks and must be restricted to isolated, out-of-band management VLANs with strict zero-trust access controls. Furthermore, security operations teams must perform forensic audits of FMC instances—specifically inspecting webroot directories like CSM Tomcat for unauthorized JSP/JAR files, checking modified system files, reviewing authentication logs for anomalous HTTP requests, and rotating all shared administrative and device credentials stored within the console.
Read original source