< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 6 sources · 25 days · First seen · Last updated

Cisco firewall software exploitation

Overview

In August 2026, a high-severity vulnerability (CVE-2026-20349) was identified as being actively exploited in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This flaw, carrying a CVSS score of 8.6, allowed unauthenticated remote attackers to trigger a denial-of-service condition via specially crafted HTTP requests.

By September 2026, the situation escalated with the discovery of a maximum-severity authentication bypass vulnerability (CVE-2026-20079) affecting Cisco Secure Firewall Management Center (FMC) software. This flaw carries a CVSS score of 10.0 and enables unauthenticated remote attackers to execute commands with root privileges.

Cisco Talos linked the exploitation of the FMC flaw to three distinct groups: UAT-12197, which plants web shells; an advanced persistent threat actor with tooling overlapping with Sandworm; and UAT-11988, which has been observed deploying Qilin ransomware. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating that federal agencies secure affected systems.

Entities

IDC · Cisco · Cisco Talos · Sandworm

Timeline

  1. 2 days ago

    [TECHNOLOGY] 6 sources
    Cisco confirms active exploitation of critical Secure FMC flaw

    Cisco confirmed that a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure FMC software is being actively exploited by multiple threat groups, including actors linked to Sandworm.

  2. 26 days ago

    [TECHNOLOGY] 2 sources
    Cisco firewalls face active exploitation of high-severity vulnerability

    Hackers are actively exploiting a high-severity Cisco firewall vulnerability (CVE-2026-20349) to cause denial-of-service disruptions via unauthenticated remote HTTP requests.

Sources

cybernoz.com · drweb.de · forkast.news · securityaffairs.co · technadu.com · tomshw.it