CVE Tools
Back to feed
Exploited in the wild Cisco Secure Firewall Management Center (FMC) Sandworm auth-bypass Cisco Qilin

Organizations Warned of Cisco Secure FMC Exploitation

SecurityWeek·By Eduard Kovacs··2 min read
CVE Tools coverage

Cisco and CISA have confirmed active in-the-wild exploitation of CVE-2026-20079, a critical authentication bypass flaw in Cisco Secure Firewall Management Center (FMC). This vulnerability permits remote attackers to execute arbitrary scripts and gain root access by sending crafted HTTP requests to vulnerable systems. Talos has linked the attacks to Russian APT group Sandworm, which deployed Cyclops Blink malware, and the Qilin ransomware syndicate, which used the breach for reconnaissance and credential theft. Organizations should apply the patch released in early March and restrict internet-facing exposure of the FMC interface.