Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
ID: f657fcc4-57d8-5792-af7f-018ed028fc85
STIX ID: report--f657fcc4-57d8-5792-af7f-018ed028fc85
Feed Name: Help Net Security
Cisco Talos reports active exploitation of two critical FMC web-interface vulnerabilities (CVE-2026-20079 and CVE-2026-20316) that enable unauthenticated root access or login via static credentials; three intrusion clusters have been observed, including activity attributed to state-sponsored Sandworm and a Qilin ransomware operator, using web shells, malicious JARs, implants, credential harvesting, and ransomware deployment. Talos and Cisco have released hotfixes, published related IOCs, and recommend applying fixes immediately or blocking FMC management access from the Internet as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
