HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Authentication Bypass (CVE‑2026‑20079) and Credential Flaw (CVE‑2026‑20316) in Cisco FMC Leveraged by Ransomware and State‑Sponsored Actors

Cisco Talos reports that CVE‑2026‑20079 and CVE‑2026‑20316 in Secure Firewall Management Center were exploited by ransomware and state‑sponsored groups, leading to credential theft and ransomware deployment. The event highlights the importance of rapid patching and privileged‑account controls for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Critical Cisco FMC Authentication Bypass (CVE‑2026‑20079) and Credential Flaw (CVE‑2026‑20316) Exploited by Ransomware and State‑Sponsored Actors

What Happened — Cisco Talos disclosed that two newly‑patched vulnerabilities in Secure Firewall Management Center (FMC) – CVE‑2026‑20079 (unauthenticated authentication bypass, CVSS 10.0) and CVE‑2026‑20316 (static low‑privilege credential use, CVSS 5.3) – were actively leveraged by three threat clusters. The attackers used the flaws to install web shells, harvest internal credentials, create reverse‑SSH tunnels, and ultimately deploy Qilin ransomware and Cyclops Blink malware on compromised networks.

Why It Matters for Trust & Control Assurance

  • Continuous vulnerability management and rapid patch adoption are core evidence that an organization’s control‑assurance program is functioning.
  • The incident underscores the need for strong privileged‑account controls (MFA, least‑privilege, audit logging) to prevent credential‑based abuse.
  • Demonstrating timely remediation and monitoring of FMC activity provides defensible audit evidence across multiple frameworks.

Who Is Affected — Any enterprise that deploys Cisco Secure Firewall Management Center, spanning sectors such as finance, healthcare, technology, and government.

Recommended Actions

  • Apply Cisco’s hot‑fixes for CVE‑2026‑20079 and CVE‑2026‑20316 without delay.
  • Run a post‑patch vulnerability scan to confirm remediation.
  • Enforce MFA and least‑privilege for all FMC admin accounts.
  • Enable continuous logging and alerting on FMC for anomalous commands or web‑shell uploads.
  • Document remediation steps and monitoring results as part of your audit evidence package.

Technical Notes

  • Attack vector: exploitation of a remote authentication bypass (CVE‑2026‑20079) and a static credential flaw (CVE‑2026‑20316).
  • Impact: credential theft, internal network reconnaissance, deployment of ransomware (Qilin) and espionage malware (Cyclops Blink).
  • References: Cisco Talos report, CVE entries, patch advisories. Source: https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
📰 Original Source
https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →