Cisco recently announced that two critical vulnerabilities in their Secure Firewall Management Center (FMC) have been exploited by threat actors associated with ransomware and state-sponsored attacks.
The first vulnerability, CVE-2026-20079, with a CVSS score of 10.0, allows remote attackers to bypass authentication and gain root access to the operating system. The second flaw, CVE-2026-20316, with a CVSS score of 5.3, enables unauthorized access to sensitive data on affected devices.
Cisco Talos identified three distinct threat clusters exploiting these vulnerabilities. The first cluster, UAT-12197, used CVE-2026-20079 to deploy web shells and command executors to extract user credentials. The second cluster, UAT-11823, exploited both vulnerabilities to deliver malicious scripts and malware, including a variant of the Russian hacking group Sandworm’s Cyclops Blink implant. The third cluster, UAT-11988, conducted a ransomware operation by leveraging CVE-2026-20316 for initial access and deploying ransomware on selected systems.
Cisco recommends applying the hotfixes for CVE-2026-20079 and CVE-2026-20316 and plans to release a comprehensive hardening update for other vulnerabilities soon.
In response to these exploits, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, mandating Federal agencies to patch by a certain date. The second vulnerability, CVE-2026-20316, was also added to the catalog in July 2026.

