OTX-6aa1c2281252d98a241ae632
info
📛 Threat Title
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Description
Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately. Pulse contains 10 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (10)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2025-20333
IOC database
- Type
- cve
- Value
CVE-2025-20333- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2025-20362
IOC database
- Type
- cve
- Value
CVE-2025-20362- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-20182
IOC database
- Type
- cve
- Value
CVE-2026-20182- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-20316
IOC database
- Type
- cve
- Value
CVE-2026-20316- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2026-20079
IOC database
- Type
- cve
- Value
CVE-2026-20079- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
208.123.119.215
VT 4 / 89
IOC database
- Type
- ipv4
- Value
208.123.119.215- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- CC=US ASN=AS395092 shock hosting llc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 89 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ArcSight Threat Intelligence | malicious | malware |
| Fortinet | malicious | malware |
| SOCRadar | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 208.123.116.0/22 |
| Country | US |
| AS owner | Shock Hosting LLC |
| ASN | 395092 |
| Regional registry | ARIN |
History
| Last analysis | 2026-09-10 23:34 UTC |
| Last modified on VirusTotal | 2026-09-10 23:40 UTC |
| WHOIS record date | 2026-09-05 13:17 UTC |
hash_sha256
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461
VT: not in VT
IOC database
- Type
- hash_sha256
- Value
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
hash_sha256
b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d
VT: not in VT
IOC database
- Type
- hash_sha256
- Value
b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
hash_sha256
db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
IOC database
- Type
- hash_sha256
- Value
db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
ipv4
91.214.78.118
VT 3 / 89
IOC database
- Type
- ipv4
- Value
91.214.78.118- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 89 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ArcSight Threat Intelligence | malicious | malware |
| Fortinet | malicious | malware |
| SOCRadar | malicious | phishing |
Details From VirusTotal
Basic Properties
| Network | 91.214.78.0/24 |
| Country | GE |
| AS owner | Merenyuk Nikita Vladimirovich |
| ASN | 200579 |
| Regional registry | RIPE NCC |
History
| Last analysis | 2026-09-10 23:34 UTC |
| Last modified on VirusTotal | 2026-09-11 00:58 UTC |
| WHOIS record date | 2026-09-09 20:15 UTC |
References (2)
- reference AlienVaulkt OTX
-
OTX pulse
AlienVaulkt OTX
Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 d
Remediations (8)
-
web:aicybr.com
Cisco updated its Secure Firewall Management Center (FMC) advisory on September 9, 2026 to confirm active exploitation of CVE-2026-20079, a CVSS 10.0 authentication-bypass vulnerability that can give an unauthenticated remote attacker root access to an affected FMC system.
-
web:arcticwolf.com
CVE-2026-20316, CVE-2026-20079: Active Exploitation of Cisco Secure Firewall Management Center Zero-Day CVE-2026-20316 is an actively exploited Cisco FMC zero-day that could enable unauthorized access and lead to full system compromise when chained with other vulnerabilities . Review the risks and mitigation steps.
-
web:blog.talosintelligence.com
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco's Secure Firewall Management Center (FMC) Software.
-
web:sec.cloudapps.cisco.com
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java ...
-
web:sec.cloudapps.cisco.com
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this ...
-
web:securityarsenal.com
CISA confirms active exploitation of CVE-2026-20316 in Cisco FMC. Immediate patching and forensic triage required per BOD 26-04.
-
web:socprime.com
Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information.
-
web:www.bleepingcomputer.com
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Reputation of linked indicators
DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.