Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0

Cisco Talos, the company's threat intelligence unit, confirmed on September 9, 2026 that attackers are exploiting a maximum-severity flaw in Cisco Secure Firewall Management Center (FMC), the central console administrators use to run an organisation's firewalls. Cisco's advisory rates the bug, tracked as CVE-2026-20079, at CVSS 10.0 - the highest score the scale allows.
Cisco describes it as an authentication bypass: an unauthenticated remote attacker can send crafted HTTP requests to the FMC web interface and execute scripts and commands with root privileges. Anyone able to reach the management console over the network can take it over without a password - and with it, the firewalls it manages.
The timeline explains the September alarm. Cisco first published the advisory on March 4, 2026, after Brandon Sakai of Cisco found the flaw during internal security testing, with no sign of abuse at the time. The document now states that "in August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability"; Cisco updated it to version 2.5 on September 9, 2026. The US Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog the same day and gave federal civilian agencies until September 12, 2026 to remediate - a three-day window.
Talos is tracking three separate intrusion clusters. It assesses with high confidence that UAT-11823 is an advanced persistent threat actor whose tooling overlaps with that of Sandworm, the Russian APT group, and says the cluster deployed Cyclops Blink malware previously attributed to Sandworm. It assesses, also with high confidence, that UAT-11988 is a ransomware operator whose techniques are consistent with those of Qilin affiliates, stopping short of naming the group outright. A third cluster, UAT-12197, deployed web shells and a JAR-based command executor and exfiltrated credentials; Talos offers no attribution for it.
A second FMC vulnerability appears in the same coverage and should not be confused with this one. CVE-2026-20316 is a hard-coded password flaw scored 5.3 by Talos and reported by Jimi Sebree of Horizon3.ai; CISA added it to the KEV catalog on July 29, 2026 with an August 1 deadline. According to Talos, both the Sandworm-linked and the Qilin-linked cluster chained it with the authentication bypass.
Why this matters: Cisco says there is no workaround and that upgrading to a fixed release is the only remedy, and it has issued hot fixes for FMC versions 7.0 through 10.0. What remains unknown is scale - neither Cisco nor Talos published how many organisations were breached or how many FMC systems are exposed. BleepingComputer reported on September 10, 2026 that Cisco planned a more comprehensive hardening release the following week.
Sources
- Cisco Talos IntelligencePrimary source
- Cisco Security Advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2Primary source
- CISA Known Exploited Vulnerabilities CatalogPrimary source
- BleepingComputerSecondary
- Help Net SecuritySecondary
Related
Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22
Trending now
- King Charles Convenes AI Leaders in Scotland, Palace Confirms
- Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
- Celine Dion Opens 16-Show Paris Run, First Concert in 6 Years
- Zverev Beats Shelton in 4 Sets for First US Open Title
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
Comments
No comments yet. Be the first.