< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

Cisco confirms active exploitation of critical Secure FMC flaw

Cisco has confirmed that a maximum-severity authentication bypass vulnerability, tracked as CVE-2026-20079, is being actively exploited in attacks. The flaw, which carries a CVSS score of 10.0, affects Cisco Secure Firewall Management Center (FMC) software and allows unauthenticated remote attackers to execute commands with root privileges.

Cisco Talos has linked the exploitation to three separate groups. One cluster, UAT-12197, has been used to plant web shells and extract authentication data. A second cluster, UAT-11823, is attributed to an advanced persistent threat actor with tooling overlapping with Sandworm. A third group, UAT-11988, has been observed deploying Qilin ransomware following credential theft.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure affected systems by September 12, 2026. Cisco recommends that customers upgrade to the latest software release immediately, as there are no available workarounds.

Entities

Cisco Talos · Sandworm