Full Report
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
Analysis Summary
# Vulnerability: Active Exploitation of Cisco Secure FMC
## CVE Details
- **CVE ID:** CVE-2026-20079
- **CVSS Score:** 10.0 (Critical)
- **CWE:** Authentication Bypass
- **CVE ID:** CVE-2026-20316
- **CVSS Score:** 5.3 (Medium) - *Note: Used in chains to elevate privileges.*
- **CWE:** Static Credentials / Low-privileged Access
## Affected Systems
- **Products:** Cisco Secure Firewall Management Center (FMC) Software (On-Premises).
- **Versions:** All versions prior to the September 2026 hotfixes/hardening release.
- **Configurations:** Unpatched instances of FMC; instances exposed to the network allowing remote access.
## Vulnerability Description
**CVE-2026-20079:** A critical authentication bypass flaw that allows a remote, unauthenticated attacker to bypass security checks. This grants the ability to execute arbitrary scripts on the impacted device, ultimately leading to **root access** to the underlying operating system.
**CVE-2026-20316:** A vulnerability involving the use of static credentials that allows a remote attacker to log in using a low-privileged account. While lower in severity, it is actively used as an entry point to chain with other flaws for full system compromise.
## Exploitation
- **Status:** **Exploited in the wild.** Active targeting by state-sponsored (Sandworm), crimeware, and ransomware (Qilin) actors.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Root access, credential exfiltration from internal databases).
- **Integrity:** High (Deployment of web shells, JAR-based executors, and malware like Cyclops Blink).
- **Availability:** High (Potential for ransomware encryption of endpoints and system takeover).
## Remediation
### Patches
- **Hotfixes:** Cisco has released immediate hotfixes for both CVEs.
- **Hardening Release:** A comprehensive software update including these fixes and additional security hardening is scheduled for the **week of September 14, 2026**.
### Workarounds
- No specific workarounds are provided; immediate patching/hotfix application is the primary recommendation.
- Restrict network access to the FMC management interface to trusted internal IPs only.
## Detection
### Indicators of Compromise (IoCs)
- **Web Shells:** `home[.]jsp` (SHA256: `b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d`)
- **Malicious Tools:** `cmd[.]jar` (Command executor), `socks5.py`, and `Cyclops Blink` malware variants.
- **Network IPs:**
- `104.218.165[.]253` (Vulnerability scanning)
- `89.34.96[.]56`, `208.123.119[.]215`, `91.214.78[.]118` (Reverse shell C2)
- `43.204.2[.]142` (Qilin affiliate intrusion IP)
### Detection Methods
- **Snort SIDs:**
- CVE-2026-20079: `66075` – `66080`
- CVE-2026-20316: `66883`
- Malware/C2: `66960`, `66961`
- **Audit Logs:** Check for unusual `OmniQuery.pl` executions or unexpected JAVA processes originating from the Tomcat webroot.
## References
- **Cisco Advisory (CVE-2026-20079):** hxxps://sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
- **Cisco Advisory (CVE-2026-20316):** hxxps://sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- **Talos Intelligence Blog:** hxxps://blog[.]talosintelligence[.]com/active-exploitation-cisco-fmc-vulnerabilities/
- **IoC Repository:** hxxps://github[.]com/Cisco-Talos/IOCs/tree/main/2026/09