Cisco logo displayed against a red-toned cybersecurity threat graphic

Critical Cisco Firewall Bug Under Attack by Sandworm APT

Two Cisco bugs, three attackers, one root-access foothold: patches exist, but Cisco’s own broader fix is still days away.

A critical firewall-management flaw Cisco disclosed in March is now being actively exploited by three separate attackers: a Russian state-linked group and a ransomware crew among them, confirming what security teams feared.

The more severe of the two bugs, CVE-2026-20079, is an unauthenticated remote authentication-bypass flaw in Cisco’s Secure Firewall Management Center (FMC) software that lets an attacker execute scripts with root access. It carries a CVSS score of 10.0, the maximum possible. A Cisco’s advisory published Wednesday said “an attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device.”

Beyond the Break weekly cybersecurity newsletter — Subscribe

The second bug, tracked as CVE-2026-20316, lets a remote attacker log into a Cisco Secure Firewall Management Center (previously called Firepower Management Center) device using a low-privileged account. Cisco rates it a comparatively modest 5.3, however researchers at Cisco Talos explain attackers can chain it with the auth-bypass flaw (CVE-2026-20079) to escalate access. And some attackers have.

Cisco Talos disclosed the active exploitation Tuesday, and found three separate groups of attackers behind it and each with a different playbook.

Three Attackers, Three Playbooks

“Talos’ analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors,” wrote Cisco Talos.

The first cluster, which Talos tracks as UAT-12197, planted a Java-based web shell in the FMC’s Tomcat webroot, then used it to drop a command-executor JAR file and pull credentials straight out of the system’s internal database.

The second, UAT-11823, Talos attributes it “with high confidence” to an advanced persistent threat actor overlapping with Sandworm. That is the Russian military-linked group the U.S. and U.K. have tied to the Cyclops Blink malware.

In the case of UAT-11823 researchers said adversaries have chained both CVEs, planted a Netcat-based reverse shell, and ultimately deployed a Cyclops Blink variant capable of credential harvesting, packet sniffing, and arbitrary command execution.

The third, UAT-11988, wants money, not access for its own sake. Talos assesses with high confidence it’s a Qilin ransomware operator. The group skipped the auth-bypass bug entirely, logging in via the static-credential flaw (CVE-2026-20316), then living off the land with FMC’s own built-in tooling. Next it harvested Active Directory and MySQL credentials, mapping domain controllers and file servers, and tunneling into the network over LDAP, Kerberos, SMB, and WinRM before deploying Qilin ransomware on selected endpoints.

What’s affected, what to do

“Due to Talos identifying in the wild abuse of these CVE’s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316,” Cisco wrote.

The flaw affects FMC software across the 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 release branches, plus Cisco Security Cloud Control’s SaaS-delivered Firewall Management – though Cisco has already patched the cloud-hosted version on its end. Cisco has released hotfixes for each affected branch, however no workarounds exist.

Cisco says a broader hardening release bundling these hotfixes with other internally discovered vulnerabilities is coming next week. Neither Cisco’s advisory nor Talos’s post agrees on which week. Each share two different dates. The takeaway is treat “next week” loosely until Cisco locks it down.

Administrators running FMC should apply the hotfixes now, not wait for the bundled release. Talos has also published indicators of compromise for all three clusters.

Cisco Security Advisory and Hotfix CVE-2026-20079

Cisco Security Advisory and Hotfix CVE-2026-20316

Total
0
Shares
Previous Article
Illustration of U.S. and Chinese AI chips exchanging data through a funnel representing AI model distillation.

China Pushes Back on U.S. AI Model Extraction Claims

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading