HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Two Critical Cisco Firewall Flaws (CVE‑2026‑20079, CVE‑2026‑20316) Exploited by Sandworm and Ransomware Actors

Cisco disclosed two remote‑code‑execution bugs in its Secure Firewall Management Center that were leveraged by Sandworm‑linked and ransomware groups to install web shells and steal credentials. The incidents highlight the need for continuous access‑control assurance and auditable remediation.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 databreachtoday.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
databreachtoday.com

Two Critical Cisco Firewall Flaws (CVE‑2026‑20079, CVE‑2026‑20316) Exploited by Sandworm and Ransomware Actors

What Happened — Cisco disclosed two high‑severity bugs in its Secure Firewall Management Center (on‑prem and cloud). CVE‑2026‑20079 is an unauthenticated authentication‑bypass that lets an attacker execute commands at boot time. CVE‑2026‑20316 is a hard‑coded password issue that permits low‑privilege logins and privilege escalation. Cisco’s Talos team observed three post‑compromise clusters that leveraged one or both flaws, including a Sandworm‑linked group that deployed the Cyclops Blink malware and harvested credentials.

Why It Matters for Trust & Control Assurance

  • The flaws illustrate a classic failure of access‑control safeguards that a continuous‑control‑assurance program is built to detect, remediate, and evidence.
  • Demonstrating timely patching, credential hygiene, and immutable configuration changes provides defensible audit evidence across frameworks (e.g., NIST CSF 2.0).
  • Verisq’s Access Controls capability can ingest firewall patch status, login anomaly data, and remediation tickets to produce a real‑time trust posture that auditors can verify.

Who Is Affected – Enterprises that rely on Cisco Secure Firewall (on‑prem or cloud), spanning technology/SaaS providers, financial services, healthcare, and any sector with regulated data.

Recommended Actions

  • Apply Cisco’s security patches for CVE‑2026‑20079 and CVE‑2026‑20316 immediately.
  • Verify firmware versions across all managed firewalls and enforce a strict patch‑management schedule.
  • Conduct a privileged‑account review to locate and rotate any static or hard‑coded credentials.
  • Enable continuous logging and integrate firewall logs with a control‑mapping platform to prove remediation. Source: DataBreachToday

Technical Notes – The authentication‑bypass bug is a boot‑time HTTP request injection that leads to remote code execution (root). The hard‑coded password bug allows unauthenticated login with a low‑privilege account, which can be chained with other bugs for privilege escalation. Both were used to plant web shells, JAR‑based executors, and the Cyclops Blink malware. Source: Cisco Talos advisory

📰 Original Source
https://www.databreachtoday.com/cisco-firewall-bugs-let-in-sandworm-qilin-a-32793

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →