If you manage Cisco Secure Firewalls through a Firewall Management Center (FMC) appliance, stop what you’re doing and check your patch status. A maximum-severity authentication bypass — CVE-2026-20079, CVSS 10.0 — is being actively exploited by three distinct threat clusters, including a Qilin ransomware operation and a Russian state-sponsored group linked to Sandworm. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on September 10 with a September 12 remediation deadline for federal agencies. That two-day window should tell you everything about the urgency here.
What the Vulnerability Is
CVE-2026-20079 is an authentication bypass vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) software. It allows an unauthenticated, remote attacker to bypass authentication entirely and execute arbitrary script files on the affected device. Once exploited, the attacker gains root access to the underlying operating system. No credentials required. No user interaction needed. It gets a 10.0 for a reason.
Cisco originally disclosed and patched this flaw in March 2026. If your FMC instance is still running a vulnerable version, you have been exposed for roughly six months.
Who Is Exploiting It
Cisco Talos published a detailed breakdown on September 10 identifying three separate clusters actively targeting FMC deployments:
UAT-12197 — Exploits CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR) command executor. Their objective is to query internal databases and steal authentication data and credentials from the FMC environment.
UAT-11823 — Exploits both CVE-2026-20079 and CVE-2026-20316 (a lower-severity info disclosure flaw also under active attack). This group delivers a Netcat-based reverse shell plus two bash scripts to harvest managed-device configurations. Critically, they also deploy Cyclops Blink — a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm.
UAT-11988 — A ransomware operation exploiting CVE-2026-20316 for initial access, then using legitimate built-in FMC tooling as part of a living-off-the-land (LotL) strategy. They conducted extensive reconnaissance, dropped tunneling tools, collected credentials, built a target list of endpoints to encrypt, terminated security software, and deployed Qilin ransomware on selected systems.
Three different operators with three different endgames — credential theft, espionage, and ransomware. The FMC console is the single most privileged management interface in your firewall infrastructure, and all three groups are going through it.
Why This Matters
The Firewall Management Center is not a perimeter device. It is the central administration console that manages every firewall in your fleet. An attacker with root access to FMC can reconfigure, disable, or monitor every firewall under its control. They can siphon VPN credentials, change access rules, disable logging, and tunnel out your network traffic — all from a single compromised console. The blast radius is enormous.
CISA’s KEV listing on September 10 makes this official: binding for federal agencies within 48 hours, and a clear prioritization signal for every private-sector security team. When CISA sets a two-day deadline on a CVSS 10.0 flaw that Cisco’s own threat intel team has confirmed is being exploited by ransomware and nation-state actors, the message is unambiguous.
What You Need to Do
1. Patch immediately. Cisco released hotfixes for CVE-2026-20079 in March 2026 and for CVE-2026-20316 in July 2026. If you deferred either one, the window for waiting closed on September 10. Apply the fixed release that addresses both vulnerabilities.
2. Inventory every FMC instance. Find every Firewall Management Center in your environment — including lab, staging, acquired, and forgotten instances. If any are exposed to the internet or reachable from non-management networks, those are your highest risk.
3. Reduce management-plane exposure. FMC administration should only be accessible from your dedicated management network. No FMC console should be reachable from the public internet or general user segments.
4. Audit for compromise. Review FMC authentication logs, look for unexpected admin accounts, check for unauthorized JSP files, web shells, and review running processes for unfamiliar binaries. A patch does not remove backdoors an attacker already planted.
5. Rotate credentials. All credentials stored in or accessible from FMC — including firewall admin passwords, VPN pre-shared keys, and any service accounts — should be rotated after patching if there is any indication of prior compromise.
The Bottom Line
CVE-2026-20079 was patched in March. It is now September. The gap between disclosure and active, diverse exploitation is exactly the window attackers used to compromise organizations that did not prioritize this fix. Qilin ransomware, credential theft, and Sandworm-linked implants are all coming through the same door. Patch your FMC instances today — not tomorrow, not next week.