Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
September 10, 2026
Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
September 10, 2026
Critical Check Point VPN Vulnerabilities Allow RCE Attacks
September 10, 2026
Home/CyberSecurity News/Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
CyberSecurity News

Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access

Key Takeaways Cisco has confirmed active exploitation of two critical vulnerabilities in its Secure Firewall Management Center (FMC) software. The most severe flaw, CVE-2026-20079, carries a CVSS...

Marcus Rodriguez
Marcus Rodriguez
September 10, 2026 4 Min Read
2 0

Key Takeaways

  • Cisco has confirmed active exploitation of two critical vulnerabilities in its Secure Firewall Management Center (FMC) software.
  • The most severe flaw, CVE-2026-20079, carries a CVSS score of 10.0 and allows unauthenticated root access.
  • State-sponsored actors, including a group linked to Russia’s Sandworm, and a Qilin ransomware affiliate are leveraging these flaws.
  • Exploitation began in August, leading to credential theft, malware deployment (including a Cyclops Blink variant), and ransomware attacks.
  • Immediate application of available hotfixes and restricting internet exposure of FMC interfaces are strongly recommended.

Cisco Secure Firewall Management Center Under Active Attack by Sophisticated Threat Actors

Cisco Talos has issued an urgent alert confirming that multiple threat actors, including state-sponsored groups and a ransomware affiliate, are actively exploiting two critical vulnerabilities within the Cisco Secure Firewall Management Center (FMC) software. These attacks have enabled adversaries to achieve root access, deploy malicious software, and initiate widespread attacks against enterprise networks.

Table Of Content

  • Key Takeaways
  • Cisco Secure Firewall Management Center Under Active Attack by Sophisticated Threat Actors
  • Critical Flaw Grants Unauthenticated Root Access
  • Secondary Vulnerability Chained for Deeper Inroads
  • Diverse Threat Actor Tactics and Payloads
  • UAT-12197: Web Shell Deployment and Credential Theft
  • UAT-11823: Sandworm’s Cyclops Blink Variant
  • UAT-11988: Qilin Ransomware Infiltration
  • What You Should Do

This disclosure represents a significant cybersecurity event for organizations globally, given the pivotal role of FMC as the central console for managing Cisco firewall deployments across various enterprise environments.

Critical Flaw Grants Unauthenticated Root Access

The more severe of the two identified vulnerabilities, tracked as CVE-2026-20079, has been assigned a maximum CVSS score of 10.0. This flaw permits an unauthenticated remote attacker to completely bypass standard login mechanisms and gain control over affected systems.

The vulnerability arises from an improperly managed system process initiated during the boot sequence of an FMC device. If this session remains unclaimed by a legitimate user, an attacker can hijack it to execute arbitrary scripts with root privileges on the underlying operating system. Although Cisco released a patch for this issue in March 2026, its Product Security Incident Response Team (PSIRT) confirmed on September 9 that in-the-wild exploitation commenced in August. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies remediate the flaw by September 12.

Secondary Vulnerability Chained for Deeper Inroads

The second vulnerability, CVE-2026-20316, presents a moderate CVSS score of 5.3. This issue stems from hard-coded, static credentials linked to a low-privileged account, allowing remote attackers to gain unauthorized access. While this flaw offers limited access on its own, Cisco Talos warns that its danger escalates significantly when combined with the authentication bypass (CVE-2026-20079) or other FMC vulnerabilities to achieve privilege escalation. Cisco identified and patched this vulnerability in late July 2026, with CISA adding it to the KEV catalog concurrently.

Diverse Threat Actor Tactics and Payloads

Cisco Talos researchers have identified three distinct clusters of post-compromise activity, each indicative of differing threat actor objectives, as detailed in Cisco Talos’s technical disclosure.

UAT-12197: Web Shell Deployment and Credential Theft

The first cluster, designated UAT-12197, leveraged the CVE-2026-20079 authentication bypass to implant a JSP-based web shell within the FMC’s Tomcat webroot directory. This was then used to deploy a Java Archive (JAR) command executor, named “cmd.jar,” specifically designed to query the device’s internal database and exfiltrate stored user credentials.

UAT-11823: Sandworm’s Cyclops Blink Variant

The second cluster, UAT-11823, is assessed with high confidence to be an advanced persistent threat (APT) actor with strong overlaps to Sandworm, a notorious group linked to the Russian military. This group chained both CVE-2026-20079 and CVE-2026-20316. Their tactics included replacing a legitimate license file with a malicious Makeself package to establish a Netcat-based reverse shell, exfiltrating device configurations, and ultimately deploying a variant of the Cyclops Blink malware. Cyclops Blink is a modular implant previously associated with Sandworm’s botnet operations targeting network edge devices. The variant discovered on compromised FMC systems offers persistence via init.d scripts, DNS-over-HTTPS command-and-control resolution, credential harvesting, packet sniffing, and arbitrary remote command execution capabilities.

UAT-11988: Qilin Ransomware Infiltration

The third cluster, UAT-11988, is attributed with high confidence to an operator of the Qilin ransomware. This group bypassed the authentication flaw, instead gaining initial access via the static-credential vulnerability (CVE-2026-20316). Once inside, they “lived off the land” by utilizing FMC’s own built-in administrative tools. Their activities included harvesting Active Directory and MySQL credentials, mapping domain controllers, file servers, and Exchange infrastructure. They then tunneled deeper into victim networks using LDAP, Kerberos, SMB, NetBIOS, and WinRM protocols via a Python SOCKS5 proxy and reverse-SSH connections, before deploying antivirus killers and the Qilin ransomware payload on selected endpoints.

What You Should Do

  • Apply Hotfixes Immediately: Cisco and Talos strongly urge all organizations running Cisco Secure FMC to apply the already-released hotfixes for CVE-2026-20079 and CVE-2026-20316 without delay. Do not wait for the broader hardening release scheduled for the week of September 14, which will bundle these fixes with additional patches.
  • Restrict Network Exposure: For administrators unable to patch immediately, it is critical to restrict Cisco FMC management interfaces from direct internet exposure. This significantly reduces the attack surface for all three observed threat campaigns.
  • Monitor for Indicators of Compromise (IOCs): Review your network logs and security telemetry for the IOCs provided by Cisco Talos to detect any signs of compromise.
  • Review Access Logs: Scrutinize FMC access logs for any unauthorized logins or suspicious activity, particularly those associated with the static credentials or attempts to bypass authentication.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVECybersecurityExploitHackerMalwarePatchransomwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Palo Alto PAN-OS Critical Vulnerability Lets Attackers Execute Code as Root
September 10, 2026
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Crypto
September 10, 2026
Critical Active Directory Flaw Lets Attackers Impersonate Domain Controllers
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us