Cisco Talos confirmed active in-the-wild abuse of two Secure Firewall Management Center (FMC) web-interface bugs: CVE-2026-20079 (CVSS 10.0 authentication bypass that lets a remote unauthenticated attacker execute scripts and obtain root) and CVE-2026-20316 (static low-privilege credentials). Cisco’s advisory for CVE-2026-20079 was updated September 9 saying the company became aware of active exploitation in August. CISA added CVE-2026-20079 to KEV with a federal fix-by date of September 12, 2026.
Talos detailed three clusters. UAT-12197 abuses CVE-2026-20079 to drop a web shell in the CSM Tomcat webroot, then a malicious JAR that harvests auth data and credentials. UAT-11823, assessed as Russian state-sponsored Sandworm, uses either flaw, tampers with license.tmp for a reverse shell, steals managed-firewall configs, and deploys a Cyclops Blink-family implant (file transfer, credential harvest, command execution, sniffing, scanning). UAT-11988, assessed as a Qilin ransomware operator, lands via CVE-2026-20316 static credentials, then recon, credential theft, AV killers, and ransomware delivery.
CVE-2026-20079 was found internally (Brandon Sakai), patched/disclosed March 2026; CVE-2026-20316 (Horizon3.ai / Jimi Sebree) shipped July 29 with earlier KEV listing. Hotfixes exist for FMC 7.0 / 7.2 / 7.4 / 7.6 / 7.7 / 10.0 per Cisco’s advisory. Cisco flags a broader hardening release for the week of September 16 — apply the published hotfixes now, and keep the FMC management plane off the public internet as the temporary control. Victim count: Undisclosed; sources are Talos cluster IDs and the advisory.
Underwrite sheet — sourced only: CVE-2026-20079 CVSS 10 auth bypass + CVE-2026-20316 static creds; Talos UAT-12197 / UAT-11823 (Sandworm / Cyclops Blink) / UAT-11988 (Qilin); CISA KEV due Sep 12; hotfixes now, hardening week of Sep 16. Primary is Cisco’s security advisory. SecurityWeek and Help Net Security for the Talos cluster framing.
