# Cisco firewall software exploitation

> Live situation record from CLSTR: https://clstr.news/situations/cisco-firewall-software-exploitation
> Updated: 2026-09-09T22:15:03.000Z. Sources: 6. Developments: 2.

In August 2026, a high-severity vulnerability (CVE-2026-20349) was identified as being actively exploited in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This flaw, carrying a CVSS score of 8.6, allowed unauthenticated remote attackers to trigger a denial-of-service condition via specially crafted HTTP requests.

By September 2026, the situation escalated with the discovery of a maximum-severity authentication bypass vulnerability (CVE-2026-20079) affecting Cisco Secure Firewall Management Center (FMC) software. This flaw carries a CVSS score of 10.0 and enables unauthenticated remote attackers to execute commands with root privileges.

Cisco Talos linked the exploitation of the FMC flaw to three distinct groups: UAT-12197, which plants web shells; an advanced persistent threat actor with tooling overlapping with Sandworm; and UAT-11988, which has been observed deploying Qilin ransomware. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating that federal agencies secure affected systems.

## Timeline

### 2026-09-09: Cisco confirms active exploitation of critical Secure FMC flaw

Cisco confirmed that a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure FMC software is being actively exploited by multiple threat groups, including actors linked to Sandworm.

6 sources. https://clstr.news/cluster/cisco-confirms-active-exploitation-of-critical-secure-fmc-flaw

### 2026-08-16: Cisco firewalls face active exploitation of high-severity vulnerability

Hackers are actively exploiting a high-severity Cisco firewall vulnerability (CVE-2026-20349) to cause denial-of-service disruptions via unauthenticated remote HTTP requests.

2 sources. https://clstr.news/cluster/cisco-firewalls-face-active-exploitation-of-high-severity-vulnerability

---
Cite as: Cisco firewall software exploitation. CLSTR, https://clstr.news/situations/cisco-firewall-software-exploitation
