Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
ID: 2772d88c-70a1-56d2-acbd-f5cd660b1374
STIX ID: report--2772d88c-70a1-56d2-acbd-f5cd660b1374
Feed Name: cybersecurityNews.com
Cisco Talos confirms active exploitation of two critical vulnerabilities in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079 (auth bypass, CVSS 10.0) and CVE-2026-20316 (static credentials). Three distinct post-compromise clusters were observed — an unattributed actor deploying a JSP web shell and credential-harvesting JAR, a Sandworm-linked campaign chaining both CVEs to deploy Cyclops Blink, and a Qilin ransomware affiliate abusing static credentials to map networks, tunnel internally, and deliver ransomware. Talos and Cisco urge immediate application of available hotfixes and restricting FMC management interfaces from Internet exposure; multiple IOCs and indicators are provided and CISA has added the issues to its KEV catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
