Cisco Talos confirmed on September 9 that it is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center, the console many enterprises use to centrally administer their firewall fleet. One of them, CVE-2026-20079, is a CVSS 10.0 authentication bypass that lets a remote, unauthenticated attacker execute commands and obtain root access to the underlying device. The second, CVE-2026-20316, is a lower-severity static-credential flaw that Cisco fixed and CISA added to its Known Exploited Vulnerabilities catalog back in July.

What makes this notable is who is using the same two bugs. Talos identified three distinct intrusion clusters. One deploys web shells and a credential-harvesting Java tool. A second, which Talos attributes with high confidence to the Russian state-sponsored group Sandworm, uses the access to deploy a variant of the Cyclops Blink malware previously linked to Sandworm by U.S. and UK authorities. The third cluster, assessed as a ransomware operator, logs in with the static credentials from CVE-2026-20316 and then uses Cisco’s own built-in tooling to conduct reconnaissance, harvest credentials and build a target list for encryption, in a pattern consistent with Qilin ransomware affiliates.

The original insight worth sitting with is not that a critical firewall-management flaw is under attack; that happens regularly. It is that CVE-2026-20316, the credential used by the ransomware cluster, has been publicly known, patched and listed on CISA’s exploited-vulnerabilities catalog since July. Nation-state and ransomware operators converging on the same access point isn’t just a coincidence of interest, it’s a signal that the organizations getting hit are the ones that missed a six-week-old patch window, on a device sitting at the center of their network’s trust boundary. Cisco has additional hotfixes and a broader hardening release planned for the week of September 14, addressing further internally discovered issues in the same product. Security teams running FMC should treat every day between now and then as exposure, not routine patch cadence.

Source: Cisco Talos. See also our related coverage of a separate root-access flaw in Cisco Nexus switches and a similar chained authentication-bypass flaw in FreeIPA.