Critical 10.0
CVE-2026-20079
Exploitation of Cisco Secure Firewall Management Center Vulnerabilities by Sandworm and Qilin Ransomware Group
Vendor / product: Cisco Secure Firewall Management Center (FMC)
Event date: 2026-09-09
Public PoC: Yes
First tracked by RiskWire: 2026-09-06
Named threat actors
SandwormQilin
Sources & citations (12)
- The 36-Day Zero-Day: How Authentication Failures Are Breaking Enterprise Management Planes tech.yahoo.com · 2026-09-07
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers bleepingcomputer.com · 2026-09-10
- Three Threat Actor Clusters Including Sandworm Are Actively Exploiting Cisco FMC's CVSS 10.0 Authentication Bypass tech.yahoo.com · 2026-09-10
- U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog securityaffairs.com · 2026-09-10
- Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) helpnetsecurity.com · 2026-09-10
- Organizations Warned of Cisco Secure FMC Exploitation securityweek.com · 2026-09-10
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware thehackernews.com · 2026-09-11
- Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware cybersecuritynews.com · 2026-09-10
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline thehackernews.com · 2026-09-10
- The firewall's management console was itself the target threatroad.substack.com · 2026-09-10
- Daily OT Security News: September 10, 2026 securityboulevard.com · 2026-09-10
- Three Strikes on the Firewall Management Plane: Cisco FMC Logs Its Third CISA KEV of 2026 tech.yahoo.com · 2026-09-12
References
See CVE-2026-20079 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →