Cisco Talos: Two FMC Flaws Exploited by Three Threat Clusters
Cisco Talos disclosed on 9 September 2026 that two patched flaws in the web interface of Cisco Secure Firewall Management Center were being exploited in the wild by three separate threat clusters. CVE-2026-20079 carries a CVSS score of 10.0 and allows pre-authentication root access, while CVE-2026-20316 (5.3) is a static credential issue; chained, they give control over the managed firewall fleet.
- CVE-2026-20079: pre-auth bypass, CVSS 10.0, fixed in March 2026
- CVE-2026-20316: static credentials, CVSS 5.3, fixed 29 July 2026
- Talos tracked UAT-12197, UAT-11823 (Sandworm-linked) and UAT-11988 (Qilin affiliate)
- Cisco advises removing management interfaces from the internet and checking license.tmp
Read next
Security