logo

Cisco Secure Firewall Exploitation: Critical Flaws Enable Root Access

ID: bba75ebf-4ce4-5e01-89e7-6cf25be5debf

STIX ID: report--bba75ebf-4ce4-5e01-89e7-6cf25be5debf

Feed Name: CyberNexora News

Threat Score
90/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Debolina Barik

...
...

The report documents active exploitation of Cisco Secure Firewall Management Center vulnerabilities—most critically CVE-2026-20079 (CVSS 10.0 authentication-bypass) and CVE-2026-20316 (static credentials)—observed since August 2026; attackers achieved root-level FMC access, deployed JSP web shells and malicious JARs, and conducted credential harvesting and reconnaissance, with activity linked to Cyclops Blink/Sandworm and Qilin ransomware affiliates; Cisco Talos urges immediate hotfix application and provides IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.