CVE Tools
Back to feed
Exploited in the wild Secure Firewall Management Center Sandworm nation-state Cisco malware

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

Dark Reading·By Jai Vijayan··4 min read
CVE Tools coverage

Researchers confirm that Sandworm-linked actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) to deploy an updated version of the Cyclops Blink malware implant. By chaining a maximum severity authentication bypass flaw (CVE-2026-20079) with a secondary privilege escalation bug (CVE-2026-20316), the threat actor establishes a reverse shell before installing the 64-bit Linux-capable malware.

This newer variant expands traditional capabilities to include active network scanning and live traffic capture, posing a significant risk to organizations relying on these appliances for network management. Cisco has released emergency hotfixes for both CVEs and urges immediate application due to confirmed in-the-wild exploitation, with a broader hardening release expected shortly.