{
  "id": 6746792,
  "title": "Cisco flags active attacks through critical FMC flaws",
  "url": "https://urgent.news/2026/09/11/cisco-flags-active-attacks-through-critical-fmc-flaws",
  "topic": "world",
  "section": "World",
  "published": "2026-09-11T10:21:05.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/cisco-flags-active-attacks-through-critical-fmc-flaws/"
  },
  "original_language": "en",
  "account": "Cisco has issued a warning about ongoing attacks exploiting two significant flaws in its Secure Firewall Management Center software. The intrusions have resulted in root-level access, credential theft, reconnaissance, and malware deployment on compromised systems. On September 9, Cisco Talos identified three groups of malicious activity linked to the two vulnerabilities, CVE-2026-20079 and CVE-2026-20316. The first flaw, rated 10.0 on the CVSS scale, permits unauthenticated remote attackers to bypass authentication and execute scripts as root. The second flaw, with a CVSS score of 5.3, poses a higher risk when combined with other vulnerabilities, as it can elevate privileges. The US Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities catalogue, prompting federal agencies to remediate affected assets by September 12. Talos traced one cluster (UAT-12197) to the exploitation of CVE-2026-20079, where attackers installed web shells and command executors, and stole credentials. Another cluster (UAT-11823) combined both flaws, deploying a Netcat-based reverse shell and proxy tools, ultimately leading to the installation of Cyclops Blink, a modular malware family associated with the Russian Sandworm group. The third cluster (UAT-11988) was attributed to a ransomware operator who gained access via the static-credential weakness. The ransomware operator then used legitimate FMC tools for reconnaissance, harvested credentials, and staged data for exfiltration. Talos linked this cluster to Qilin ransomware affiliates, who also installed SOCKS proxy and reverse-SSH tunnels to maintain access. Cisco had disclosed CVE-2026-20079 in March, and CVE-2026-20316 was published on July 29, both without workarounds, making software updates the primary remediation.",
  "summary": "Cisco has warned that attackers are actively exploiting two vulnerabilities in its Secure Firewall Management Center software, with intrusions leading to root-level access, credential theft, reconnaissance and malware deployment on compromised systems. Cisco Talos said on September 9 that it had identified three clusters of post-compromise activity involving CVE-2026-20079 and CVE-2026-20316. The…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}