Cybersecurity

Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0

Published 2 min readBy NewUJ Editorial Desk

Updated factual errors corrected

Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
Photo: Cisco
0 0
XWhatsAppTelegramLinkedIn

Cisco Talos, the company's threat intelligence unit, confirmed on September 9, 2026 that attackers are exploiting a maximum-severity flaw in Cisco Secure Firewall Management Center (FMC), the central console administrators use to run an organisation's firewalls. Cisco's advisory rates the bug, tracked as CVE-2026-20079, at CVSS 10.0 - the highest score the scale allows.

Cisco describes it as an authentication bypass: an unauthenticated remote attacker can send crafted HTTP requests to the FMC web interface and execute scripts and commands with root privileges. Anyone able to reach the management console over the network can take it over without a password - and with it, the firewalls it manages.

The timeline explains the September alarm. Cisco first published the advisory on March 4, 2026, after Brandon Sakai of Cisco found the flaw during internal security testing, with no sign of abuse at the time. The document now states that "in August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability"; Cisco updated it to version 2.5 on September 9, 2026. The US Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog the same day and gave federal civilian agencies until September 12, 2026 to remediate - a three-day window.

Talos is tracking three separate intrusion clusters. It assesses with high confidence that UAT-11823 is an advanced persistent threat actor whose tooling overlaps with that of Sandworm, the Russian APT group, and says the cluster deployed Cyclops Blink malware previously attributed to Sandworm. It assesses, also with high confidence, that UAT-11988 is a ransomware operator whose techniques are consistent with those of Qilin affiliates, stopping short of naming the group outright. A third cluster, UAT-12197, deployed web shells and a JAR-based command executor and exfiltrated credentials; Talos offers no attribution for it.

A second FMC vulnerability appears in the same coverage and should not be confused with this one. CVE-2026-20316 is a hard-coded password flaw scored 5.3 by Talos and reported by Jimi Sebree of Horizon3.ai; CISA added it to the KEV catalog on July 29, 2026 with an August 1 deadline. According to Talos, both the Sandworm-linked and the Qilin-linked cluster chained it with the authentication bypass.

Why this matters: Cisco says there is no workaround and that upgrading to a fixed release is the only remedy, and it has issued hot fixes for FMC versions 7.0 through 10.0. What remains unknown is scale - neither Cisco nor Talos published how many organisations were breached or how many FMC systems are exposed. BleepingComputer reported on September 10, 2026 that Cisco planned a more comprehensive hardening release the following week.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.