Cisco has confirmed that three unrelated groups of attackers are actively exploiting two vulnerabilities in Secure Firewall Management Center (FMC), the console many organisations use to administer their Cisco firewalls. The worse of the two, CVE-2026-20079, scores a maximum 10.0 on the severity scale — it lets an attacker with no credentials at all remotely bypass login and run commands as root. The second, CVE-2026-20316, is a lower-severity flaw involving a static, low-privilege account, but Cisco's own researchers found attackers chaining it with the first to escalate access.
According to Cisco Talos, a Qilin ransomware affiliate used the static-credential bug to get in, then quietly mapped the victim's network, harvested credentials, disabled security tools, and deployed ransomware. A separate cluster linked to the Russian state-sponsored group Sandworm used the flaws to plant a persistent backdoor implant. A third, unattributed group focused purely on stealing credentials via web shells. Cisco released hotfixes for both bugs, and the U.S. cyber agency CISA has ordered federal agencies to patch by 12 September 2026 — today.
What this means for your business
If your business or IT provider runs Cisco FMC to manage firewalls, treat this as urgent: confirm the hotfix for CVE-2026-20079 and CVE-2026-20316 is installed, not just scheduled. Because one of the exploited bugs relies on a static credential rather than a discovered password, simply "changing the admin password" does not close this gap — the fix has to come from Cisco's patch itself. Given how the ransomware crew operated (quiet reconnaissance and credential theft before anything visibly breaks), also check your FMC and firewall logs for unfamiliar admin logins, new local accounts, or outbound connections you can't explain over the past two months, since the earlier of these two flaws has been under attack since July. If you outsource your network security, ask directly whether your provider manages a Cisco FMC console and whether this patch has already been applied — don't assume it has.