Cisco Secure Firewall Exploitation: Critical Flaws Enable Root Access
ID: bba75ebf-4ce4-5e01-89e7-6cf25be5debf
STIX ID: report--bba75ebf-4ce4-5e01-89e7-6cf25be5debf
Feed Name: CyberNexora News
The report documents active exploitation of Cisco Secure Firewall Management Center vulnerabilities—most critically CVE-2026-20079 (CVSS 10.0 authentication-bypass) and CVE-2026-20316 (static credentials)—observed since August 2026; attackers achieved root-level FMC access, deployed JSP web shells and malicious JARs, and conducted credential harvesting and reconnaissance, with activity linked to Cyclops Blink/Sandworm and Qilin ransomware affiliates; Cisco Talos urges immediate hotfix application and provides IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
