Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
Read Time:3 Minute, 8 Second

Cisco has confirmed that attackers are exploiting two vulnerabilities in Secure Firewall Management Center (FMC), the administrative platform used to control fleets of enterprise firewalls. The more severe flaw can let an unauthenticated remote intruder reach the underlying operating system with root privileges, turning a central security console into a powerful foothold inside a network.

According to reporting by Cyber Security News, the observed activity includes state-sponsored groups and a ransomware affiliate. The intruders did not stop at gaining access: they deployed malware, collected credentials and positioned compromised appliances for follow-on operations. Organizations running affected releases should treat remediation as an incident-response priority rather than a routine maintenance task.

A maximum-severity path past authentication

The principal issue, CVE-2026-20079, carries a CVSS score of 10.0. It involves a system process created when an FMC appliance starts. If a legitimate user has not claimed the associated session, a remote attacker may be able to hijack it, bypass authentication and run scripts as root. No valid account is required for the attack described by Cisco.

That combination is particularly dangerous on a management appliance. FMC holds a trusted position, contains valuable configuration data and communicates with security infrastructure across the environment. Root access may allow an attacker to alter the device, conceal activity, harvest information or use its connectivity to explore protected networks.

The second vulnerability, CVE-2026-20080, provides another route into affected systems. Although its mechanics and prerequisites differ, Cisco Talos linked exploitation of both issues to real intrusions. Defenders therefore need to evaluate exposure to the complete advisory rather than focusing only on the perfect-score bug.

Malware and post-compromise activity observed

Investigators saw attackers install tooling after compromise and use the affected systems as operational footholds. That matters because patching closes the entry point but does not remove persistence that may already exist. An appliance that was internet-accessible while vulnerable should be reviewed for evidence of exploitation even after it has been upgraded.

Security teams should look for unexpected scripts, processes, accounts, scheduled activity and configuration changes. Authentication records and management traffic can reveal connections from unfamiliar addresses or unusual access times. Logs should be exported to a separate, trusted system where an intruder with appliance-level control cannot modify the evidence.

What administrators should do now

  • Identify every FMC instance, record its software version and determine whether its management interface is exposed to untrusted networks.
  • Install Cisco’s fixed release without delay and verify that the upgrade completed successfully.
  • Restrict management access to dedicated administrative networks or tightly controlled VPN paths.
  • Rotate credentials and secrets accessible from the appliance if compromise is suspected.
  • Review connected firewall devices for unauthorized policy, object or account changes.

Network segmentation can reduce the damage if an edge or management product is breached. Administrative interfaces should not be generally reachable from the internet, and access should require strong authentication through a limited set of monitored systems. Where business constraints prevent immediate patching, temporary isolation is safer than relying on the appliance to defend itself.

Why this incident deserves urgency

Security management platforms are unusually attractive targets because they combine privileged access with broad visibility. Compromising one may help an attacker learn the network, weaken enforcement and blend malicious traffic into expected administrative activity. The involvement of both state-linked operators and ransomware actors also suggests that exploitation knowledge is no longer confined to a single campaign.

Organizations should document their exposure window, preserve logs and involve incident responders when indicators appear. The central question is not simply whether the vulnerable software has been patched, but whether anyone reached it before the fix was applied. Rapid remediation paired with a focused compromise assessment offers the strongest response to an actively exploited root-access flaw.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment, use the discussion on Forum.

>> forum community

Comments

Leave a Reply