Cisco fixed CVE-2026-20079 in March 2026: an authentication bypass in Secure Firewall Management Center's web interface, caused - per Cisco's own advisory language reported by SecurityWeek - by "an improper system process that is created at boot time." Send the right crafted HTTP request to an affected device and you don't need a password; you get to run scripts and commands as root on the box that manages an organisation's firewalls. A patch existed from day one. What changed is what happened after.
Seven weeks between the first footprint and the public confirmation
Cisco's own indicators of compromise, referenced in Forkast's reporting, suggest exploitation activity was already under way by 23 July - months after the patch shipped, and weeks before Cisco's PSIRT confirmed active abuse in August. Cisco updated its advisory with those indicators on 9 September and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day, giving federal agencies until 12 September to remediate. That deadline was yesterday. The roughly seven-week gap between the earliest sign of exploitation and the public confirmation is the more useful number here than the patch date itself - a patch existing since March did nothing to stop a months-long head start for whoever found the bug first.
Three different operators, one management console
Cisco Talos's own analysis identifies three distinct clusters of post-compromise activity on exploited FMC instances, each with a different objective. UAT-12197 deployed JSP-based web shells and JAR command executors to pull authentication data out of internal databases. UAT-11823, attributed to the Russian state-linked group Sandworm, used Netcat reverse shells to harvest device configurations and deployed Cyclops Blink malware - capable of DNS-over-HTTPS resolution, credential harvesting and network scanning - onto compromised boxes. UAT-11988, a Qilin ransomware affiliate, used the same access to run reconnaissance through FMC's own legitimate utilities, build tunnelling infrastructure, and push Qilin ransomware out to endpoints reachable from the management plane. Talos's advice, in its own words, is blunt: "Customers are strongly advised to apply hotfixes for affected software versions."
The third strike this year, not the first
CVE-2026-20079 isn't Secure FMC's first appearance on CISA's exploited list in 2026. We covered CVE-2026-20316, a hardcoded-credential flaw in the same product, back in July - and per Forkast's reporting, a third FMC CVE, 2026-20131, a Java deserialization flaw, was separately exploited as a zero-day in Interlock ransomware attacks. All three share the same target: the FMC web interface, the single console an organisation uses to manage every firewall behind it. That's not a coincidence of timing so much as a pattern - the management plane that's supposed to make firewalls easier to administer is turning out to be the softest way to reach all of them at once.
A comprehensive fix is still a few days out
Cisco's hotfixes for the affected release branches - 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 - have been available since the March patch and again since the September advisory update, but per Help Net Security's coverage, a more comprehensive hardening release covering both CVE-2026-20079 and CVE-2026-20316 together isn't due until the week of 14 September. Until then, the interim advice from Cisco itself is the same advice that applies to almost every internet-facing management interface: install what's available now, and don't expose the FMC interface to the internet at all if you can avoid it.
- Apply Cisco's hotfixes for CVE-2026-20079 now if you haven't already - the federal deadline for this exact CVE passed yesterday, and three separate operators are already using it.
- Restrict FMC management interface access from the internet entirely where possible; this single step addresses the precondition all three intrusion clusters relied on.
- Hunt specifically for Cyclops Blink indicators and unexpected JSP web shells or JAR files on any FMC instance that was internet-reachable between March and September.
- Don't treat "patched in March" as evidence of safety - the indicators suggest real-world exploitation started months after the fix was available, meaning patch status alone tells you nothing about whether you were already compromised.
- Watch for Cisco's comprehensive hardening release in the week of 14 September and plan to apply it on top of the existing hotfixes, not instead of them.
A management console that's the single point of control for every firewall behind it deserves a faster patch cycle than everything else in the estate, not a slower one. If you'd like help auditing how exposed your own firewall or network management plane is, email sales@halfteck.com.