CVE Tools
Back to feed
Exploited in the wild Cisco Secure Firewall Management Center (FMC) Sandworm auth-bypass Cisco Qilin

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Help Net Security·By Zeljka Zorz··3 min read
CVE Tools coverage

Cisco has confirmed that state-sponsored group Sandworm and ransomware operators linked to Qilin are actively targeting two vulnerabilities in Secure Firewall Management Center (FMC). The flaws, identified as CVE-2026-20079 and CVE-2026-20316, allow unauthorized remote attackers to bypass authentication or log in using hard-coded credentials to gain control of the system. While CVE-2026-20316 involves static low-privileged account credentials, CVE-2026-20079 permits root-level command execution via crafted HTTP requests. Talos recommends applying existing hotfixes immediately or restricting internet access to the management interface until the full hardening release is available.