Cisco's Maximum-Severity Firewall Bug Is Under Active Attack
A Cisco firewall bug patched in March is now being exploited by Russian state hackers and a ransomware gang — here's why Indian networks should care.
If your organisation runs Cisco's Secure Firewall Management Center, the box that's supposed to lock down your network quietly became one of the easiest ways into it this year. Cisco confirmed this week that a bug it patched back in March has been under active attack since at least August — by more than one group, for more than one purpose.
What actually broke
The flaw, tracked as CVE-2026-20079, sits in the web login page of Cisco's Secure Firewall Management Center (FMC) — the console that network admins use to configure and monitor fleets of physical firewalls at once. It carries a CVSS score of 10.0, the maximum severity rating security researchers hand out, because of how little an attacker needs to pull it off: no password, no insider access, just a specially crafted request sent over the network.
The root cause is a system process that gets set up wrong every time the device boots. An attacker who spots this can slip past the login screen entirely and run commands as root — meaning full, unrestricted control of the machine, the same level of access the device's own administrators have.
Cisco disclosed and patched CVE-2026-20079 back in March 2026, and published indicators of compromise in late July for anyone who wanted to check if they'd already been hit. It wasn't until its advisory update on September 9 that the company confirmed what its threat intelligence unit, Talos, had actually found: real attackers had been using the bug since August, months after a fix was available.
Three different attackers, one open door
Talos traced the exploitation to three separate clusters of activity, each with its own goals — a reminder that a single unpatched bug rarely stays a secret to just one attacker for long:
- UAT-12197 used the flaw to plant web shells (small hidden scripts that give an attacker a permanent remote command line into a hacked server) and a custom Java-based tool for running commands, then moved on to stealing credentials.
- UAT-11823 has been linked to Sandworm, the Russian military-linked hacking unit best known for knocking out parts of Ukraine's power grid. Here it used the bug to install Cyclops Blink, malware designed to bury itself in network hardware and survive reboots or firmware resets.
- UAT-11988, believed to be tied to the Qilin ransomware gang, exploited a related flaw (CVE-2026-20316) to quietly map out victim networks, harvest credentials, and build a list of machines worth encrypting later.
A firewall is supposed to sit at the edge of a network keeping attackers out. For five months, this one was doing the opposite — and almost nobody knew.
Why Indian networks should care
Cisco's Secure Firewall line, including FMC, is deployed widely across Indian banks, telecom operators, IT service providers, and government networks — exactly the sectors CERT-In (India's Computer Emergency Response Team) has flagged repeatedly in its advisories this year for lagging patch cycles. If you've read our explainer on what a home firewall actually does, FMC is that same idea scaled up to enterprise size: one login bypass on the management console can cascade across every firewall it controls, not just a single device.
That matters more now that India's Digital Personal Data Protection (DPDP) Act is moving toward active enforcement, with breach notification obligations that get harder to explain away when the root cause is a five-month-old, publicly disclosed bug nobody patched in time. And given Sandworm's track record of going after power grids and critical infrastructure abroad, any Indian operator in energy, telecom, or finance running FMC has more reason than usual to treat this as urgent rather than routine.
What to actually do about it
- Apply Cisco's hotfix immediately if your FMC deployment hasn't already been patched.
- Check your logs against the indicators of compromise Cisco and Talos published, not just assume you're clean because you patched late.
- If you find signs of compromise, know that the hotfix alone won't undo it — Cisco says it stops future exploitation but doesn't clean an already-compromised box. That means contacting Cisco TAC, rotating credentials, and treating the device as burned rather than trusted.
- Assume systems connected to a compromised FMC instance may also need checking, since attackers had months of head start before detection.
The real lesson here isn't "patch your firewalls," which every security team already knows. It's that a public patch and a public advisory are read by defenders and attackers alike — and the gap between "a fix exists" and "the fix is actually applied everywhere" is precisely where campaigns like this one live. Five months is a long time to leave a master key sitting on the internet.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0