Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
Key Takeaways Cisco has confirmed active exploitation of two critical vulnerabilities in its Secure Firewall Management Center (FMC) software. The most severe flaw, CVE-2026-20079, carries a CVSS...
Key Takeaways
- Cisco has confirmed active exploitation of two critical vulnerabilities in its Secure Firewall Management Center (FMC) software.
- The most severe flaw, CVE-2026-20079, carries a CVSS score of 10.0 and allows unauthenticated root access.
- State-sponsored actors, including a group linked to Russia’s Sandworm, and a Qilin ransomware affiliate are leveraging these flaws.
- Exploitation began in August, leading to credential theft, malware deployment (including a Cyclops Blink variant), and ransomware attacks.
- Immediate application of available hotfixes and restricting internet exposure of FMC interfaces are strongly recommended.
Cisco Secure Firewall Management Center Under Active Attack by Sophisticated Threat Actors
Cisco Talos has issued an urgent alert confirming that multiple threat actors, including state-sponsored groups and a ransomware affiliate, are actively exploiting two critical vulnerabilities within the Cisco Secure Firewall Management Center (FMC) software. These attacks have enabled adversaries to achieve root access, deploy malicious software, and initiate widespread attacks against enterprise networks.
Table Of Content
- Key Takeaways
- Cisco Secure Firewall Management Center Under Active Attack by Sophisticated Threat Actors
- Critical Flaw Grants Unauthenticated Root Access
- Secondary Vulnerability Chained for Deeper Inroads
- Diverse Threat Actor Tactics and Payloads
- UAT-12197: Web Shell Deployment and Credential Theft
- UAT-11823: Sandworm’s Cyclops Blink Variant
- UAT-11988: Qilin Ransomware Infiltration
- What You Should Do
This disclosure represents a significant cybersecurity event for organizations globally, given the pivotal role of FMC as the central console for managing Cisco firewall deployments across various enterprise environments.
Critical Flaw Grants Unauthenticated Root Access
The more severe of the two identified vulnerabilities, tracked as CVE-2026-20079, has been assigned a maximum CVSS score of 10.0. This flaw permits an unauthenticated remote attacker to completely bypass standard login mechanisms and gain control over affected systems.
The vulnerability arises from an improperly managed system process initiated during the boot sequence of an FMC device. If this session remains unclaimed by a legitimate user, an attacker can hijack it to execute arbitrary scripts with root privileges on the underlying operating system. Although Cisco released a patch for this issue in March 2026, its Product Security Incident Response Team (PSIRT) confirmed on September 9 that in-the-wild exploitation commenced in August. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies remediate the flaw by September 12.
Secondary Vulnerability Chained for Deeper Inroads
The second vulnerability, CVE-2026-20316, presents a moderate CVSS score of 5.3. This issue stems from hard-coded, static credentials linked to a low-privileged account, allowing remote attackers to gain unauthorized access. While this flaw offers limited access on its own, Cisco Talos warns that its danger escalates significantly when combined with the authentication bypass (CVE-2026-20079) or other FMC vulnerabilities to achieve privilege escalation. Cisco identified and patched this vulnerability in late July 2026, with CISA adding it to the KEV catalog concurrently.
Diverse Threat Actor Tactics and Payloads
Cisco Talos researchers have identified three distinct clusters of post-compromise activity, each indicative of differing threat actor objectives, as detailed in Cisco Talos’s technical disclosure.
UAT-12197: Web Shell Deployment and Credential Theft
The first cluster, designated UAT-12197, leveraged the CVE-2026-20079 authentication bypass to implant a JSP-based web shell within the FMC’s Tomcat webroot directory. This was then used to deploy a Java Archive (JAR) command executor, named “cmd.jar,” specifically designed to query the device’s internal database and exfiltrate stored user credentials.
UAT-11823: Sandworm’s Cyclops Blink Variant
The second cluster, UAT-11823, is assessed with high confidence to be an advanced persistent threat (APT) actor with strong overlaps to Sandworm, a notorious group linked to the Russian military. This group chained both CVE-2026-20079 and CVE-2026-20316. Their tactics included replacing a legitimate license file with a malicious Makeself package to establish a Netcat-based reverse shell, exfiltrating device configurations, and ultimately deploying a variant of the Cyclops Blink malware. Cyclops Blink is a modular implant previously associated with Sandworm’s botnet operations targeting network edge devices. The variant discovered on compromised FMC systems offers persistence via init.d scripts, DNS-over-HTTPS command-and-control resolution, credential harvesting, packet sniffing, and arbitrary remote command execution capabilities.
UAT-11988: Qilin Ransomware Infiltration
The third cluster, UAT-11988, is attributed with high confidence to an operator of the Qilin ransomware. This group bypassed the authentication flaw, instead gaining initial access via the static-credential vulnerability (CVE-2026-20316). Once inside, they “lived off the land” by utilizing FMC’s own built-in administrative tools. Their activities included harvesting Active Directory and MySQL credentials, mapping domain controllers, file servers, and Exchange infrastructure. They then tunneled deeper into victim networks using LDAP, Kerberos, SMB, NetBIOS, and WinRM protocols via a Python SOCKS5 proxy and reverse-SSH connections, before deploying antivirus killers and the Qilin ransomware payload on selected endpoints.
What You Should Do
- Apply Hotfixes Immediately: Cisco and Talos strongly urge all organizations running Cisco Secure FMC to apply the already-released hotfixes for CVE-2026-20079 and CVE-2026-20316 without delay. Do not wait for the broader hardening release scheduled for the week of September 14, which will bundle these fixes with additional patches.
- Restrict Network Exposure: For administrators unable to patch immediately, it is critical to restrict Cisco FMC management interfaces from direct internet exposure. This significantly reduces the attack surface for all three observed threat campaigns.
- Monitor for Indicators of Compromise (IOCs): Review your network logs and security telemetry for the IOCs provided by Cisco Talos to detect any signs of compromise.
- Review Access Logs: Scrutinize FMC access logs for any unauthorized logins or suspicious activity, particularly those associated with the static credentials or attempts to bypass authentication.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.