Exploited in the wild Cisco Secure Firewall Management Center (FMC) Sandworm auth-bypass Cisco Qilin
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
CVE Tools coverage
Cisco has confirmed that state-sponsored group Sandworm and ransomware operators linked to Qilin are actively targeting two vulnerabilities in Secure Firewall Management Center (FMC). The flaws, identified as CVE-2026-20079 and CVE-2026-20316, allow unauthorized remote attackers to bypass authentication or log in using hard-coded credentials to gain control of the system. While CVE-2026-20316 involves static low-privileged account credentials, CVE-2026-20079 permits root-level command execution via crafted HTTP requests. Talos recommends applying existing hotfixes immediately or restricting internet access to the management interface until the full hardening release is available.