Cisco Talos reported active exploitation of two Cisco Secure Firewall Management Center (FMC) vulnerabilities: CVE-2026-20079, a critical CVSS 10.0 authentication-bypass flaw that lets unauthenticated remote attackers execute scripts and gain root access, and CVE-2026-20316, a CVSS 5.3 issue allowing login through a low-privileged account. Cisco has issued hotfixes for both flaws and plans a broader hardening release; organizations should apply the hotfixes immediately and review FMC systems for compromise.
Talos linked the intrusions to three post-compromise activity clusters. UAT-12197 installed a JSP web shell and command-execution JAR to steal credentials; UAT-11823 deployed reverse-shell and proxy tooling alongside Cyclops Blink; and UAT-11988 performed ransomware precursor activity consistent with Qilin affiliates. Cyclops Blink is a modular, persistent network-device malware previously associated by CISA and partner agencies with Sandworm activity, capable of encrypted command-and-control, file download, and execution.

See which actors are running it and whether you're in range.
24 events from the most recent confirmed update back to the earliest known activity.
CISA added the actively exploited Cisco Secure Firewall Management Center authentication-bypass vulnerability CVE-2026-20079 to its Known Exploited Vulnerabilities catalog.
In August 2026, Sophos researchers analyzed an x86-64 Cyclops Blink variant named timezone_check on multiple compromised Cisco Firewall Management Center devices. The Russian-linked implant used SysV init persistence and added internal service scanning, password-hash collection, payload delivery, and selective packet capture capabilities.
CISA added the Cisco FMC static-credential vulnerability CVE-2026-20316 to its Known Exploited Vulnerabilities catalog around the time Cisco disclosed and patched the flaw in late July 2026.
In July 2026, Cisco added the same indicators of compromise to advisories for CVE-2026-20079 and CVE-2026-20316, including guidance to investigate /var/log/messages for use of /var/tmp/license.tmp. Cisco said a specified July 23 sudo log entry could indicate that a Secure FMC device had been exploited.
Cisco stated that CVE-2026-20131 was being actively exploited. This vulnerability is separate from the FMC flaws CVE-2026-20079 and CVE-2026-20316 already documented in the timeline.
Cisco initially disclosed CVE-2026-20079, a CVSS 10.0 authentication-bypass vulnerability affecting Secure Firewall Management Center and Security Cloud Control Firewall Management, in March 2026. At that time, Cisco had not identified evidence that the flaw was being actively exploited.
The Interlock ransomware group reportedly exploited the separate Cisco FMC vulnerability CVE-2026-20131 as a zero-day earlier in 2026. This flaw is distinct from CVE-2026-20079 and CVE-2026-20316.
Trend Micro reported that residual VPNFilter infections persisted, with more than one-third of the original number of first-stage infections remaining despite reduced requests to a known C2 domain.
Cyclops Blink, a modular malware framework targeting network devices and replacing VPNFilter, has been deployed since at least June 2019, primarily against externally managed WatchGuard devices.
A series of disruptive attacks against Georgia was previously attributed to Sandworm.
The U.S. Department of Justice linked VPNFilter activity to Sandworm and announced efforts to disrupt the botnet.
Cisco Talos reported an increase in VPNFilter victims in Ukraine.
Cisco Talos published a series of articles describing VPNFilter, a network-device malware platform with modular traffic-manipulation, destructive, and SCADA-monitoring capabilities.
Sandworm deployed VPNFilter against targets in the Republic of Korea before the 2018 Winter Olympics.
The 2017 NotPetya operation was previously attributed to Sandworm.
Industroyer activity in 2016 was previously attributed to Sandworm.
Sandworm was previously attributed to BlackEnergy-related disruption of Ukrainian electricity infrastructure.
Gurucul published five IP addresses and three SHA-256 hashes as indicators for investigating active exploitation of Cisco FMC vulnerabilities CVE-2026-20079 and CVE-2026-20316. The notice associates the indicators with post-exploitation activity including web shells, reverse shells, proxy tooling, Cyclops Blink, credential harvesting, and Qilin ransomware activity.
Cisco released hotfixes for affected FMC versions for CVE-2026-20079 and CVE-2026-20316, and Talos urged customers to apply them immediately.
Cisco Talos linked UAT-11823 to the Russian state-sponsored Sandworm threat actor. The cluster exploited CVE-2026-20079 and CVE-2026-20316 against Cisco FMC devices and deployed Cyclops Blink malware.
UAT-11988, assessed with high confidence as a Qilin ransomware operator, exploited CVE-2026-20316, harvested credentials and conducted network reconnaissance, then deployed antivirus-killing tools and the Qilin ransomware payload to selected endpoints.
Talos identified UAT-12197 stealing FMC database credentials through a JSP web shell and command-execution JAR; UAT-11823 using reverse shells, configuration collection, and a Cyclops Blink variant; and UAT-11988 conducting Qilin-consistent ransomware precursor activity.
Cisco Talos tracked active exploitation of CVE-2026-20079, a CVSS 10.0 authentication-bypass flaw enabling unauthenticated root access, and CVE-2026-20316, which permits login with a low-privileged account, in Cisco Secure Firewall Management Center Software.
Public exploit tooling for the Cisco FMC authentication-bypass vulnerability CVE-2026-20079, including a Metasploit module and GitHub proof-of-concepts, became available shortly after Cisco's March 2026 disclosure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
28 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcemkd-cirt.mk
Open sourcecirt.gy
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcesoftware.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.