DEV Community

StarkMan
StarkMan

Posted on

Cisco FMC CVE-2026-20079: a CVSS 10.0 management-plane bypass and the clusters behind it

Cisco FMC CVE-2026-20079: a CVSS 10.0 management-plane bypass and the clusters behind it

Opening

A patch that shipped in March became an incident in September. Cisco first published the advisory for CVE-2026-20079, filed under the identifier cisco-sa-onprem-fmc-authbypass-5JPp45V2, after an internal researcher, Brandon Sakai, found the flaw. On 9 September 2026 the company updated that advisory to confirm exploitation in the wild, and CISA added the CVE to the Known Exploited Vulnerabilities catalog the same day, giving federal agencies until 12 September to remediate. The window was three days.
The flaw affects Cisco Secure Firewall Management Center (FMC) software and the Firewall Management component of Cisco Security Cloud Control. It is scored 10.0 under CVSS 3.1 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, mapped to CWE-288, authentication bypass using an alternate path or channel. A crafted HTTP request to the management interface is sufficient. Device configuration is irrelevant. Successful exploitation runs scripts on the underlying operating system as root.
The management interface is not a side door here. For most deployments it is the console.

Why the management plane is the whole story

From the data plane to the control plane

Firewall coverage tends to focus on the perimeter rule set. CVE-2026-20079 does not touch it. FMC is where policy is authored, where managed firewalls are registered, where logging is centralized, and where fleet credentials live. Reaching it means reaching the machinery that governs everything downstream.

What made this exploitable

Cisco describes the root cause as an improperly implemented system process created at startup. That is a different shape from a parser bug: the process exists from boot, and an unauthenticated request can drive it into executing code. Cisco states the flaw is independent of configuration, which removes the triage shortcut of asking whether a site has the vulnerable feature enabled.

The companion flaw

CVE-2026-20316 is the second half. It covers static, hardcoded low-privilege credentials, scored 5.3, fixed on 29 July 2026 and added to KEV the same day. Alone it is a foothold and information-disclosure problem. In the activity Cisco observed, it supplied the access that CVE-2026-20079 then escalated.

What the reporting shows

Cisco Talos attributed the observed activity to three clusters, and the differences between them are the most useful part of the public record.

UAT-12197

This cluster planted home.jsp in the CSM Tomcat webroot together with cmd.jar, a command executor, and used a built-in OmniQuery.pl to pull authentication data. Documented hashes include b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d for the JSP and db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e for the JAR.

UAT-11823

Talos assessed a high-confidence link to Sandworm. This cluster chained CVE-2026-20079 with CVE-2026-20316, rewrote license.tmp, opened a netcat reverse shell, and deployed a Linux ELF variant of Cyclops Blink, a malware family better known from the router world, with capabilities for credential theft, command execution, file transfer and packet capture. Hash: 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461.

UAT-11988

The third cluster behaves like a ransomware affiliate. It logged in with static credentials, performed living-off-the-land reconnaissance, collected credentials, disabled endpoint protection, and delivered Qilin.

Network indicators

89.34.96[.]56
208.123.119[.]215
91.214.78[.]118     reverse shell C2
104.218.165[.]253   scanning source
43.204.2[.]142
Enter fullscreen mode Exit fullscreen mode

Snort coverage maps to SIDs 66075 through 66080 for CVE-2026-20079, 66883 for CVE-2026-20316, and 66960 and 66961 for the dropped malware.

Hunting on the appliance

Cisco's own guidance for FMC is to look for the temporary files these clusters leave behind. In expert mode:

zgrep "package_info.*license" /var/log/messages*
Enter fullscreen mode Exit fullscreen mode

A match on /var/tmp/license.tmp is a strong signal.

Scale, and the limits of the estimate

VulnCheck counted roughly 300 to 700 internet-exposed FMC instances in March 2026. That number has not been refreshed, so it is a lower bound of unknown age rather than a current exposure figure. There is also an inconsistency in the public timeline: at least one indicator in circulation carries a date of 23 July, ahead of the August exploitation window Cisco describes. Indicator dates arrive from different collection systems with different clocks.

Defensive implications

  • Treat the management plane as internet-facing risk even when it is not published. The fix is a software update. Cisco's advisory points to patched releases across the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 branches, with a consolidated hardening bundle in the week of 14 September. Sites that deferred the March update carried four months of exposure before the exploitation confirmation.
  • Assume FMC compromise is fleet compromise. Rotate credentials for every device registered to the management center, not only the appliance account.
  • Hunt for the artifacts, not just the CVE. The home.jsp, cmd.jar, license.tmp and Cyclops Blink hashes are concrete. A version check will not tell you whether a cluster already finished.
  • Fix the design pattern, not only the bug. Hardcoded credentials in a management product (CVE-2026-20316) turned a medium-severity issue into the first step of an intrusion chain.

References

  • Cisco Security Advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2
  • CISA Known Exploited Vulnerabilities catalog
  • NVD, CVE-2026-20079
  • NVD, CVE-2026-20316
  • Cisco Talos
  • FreeBuf

Top comments (0)