s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-6aa1c2281252d98a241ae632 info

📛 Threat Title

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Category: UAT-12197, UAT-11823, UAT-11988, Sandworm Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately. Pulse contains 10 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (10)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2025-20333

IOC database

Type
cve
Value
CVE-2025-20333
First seen
Last seen
Attached to this threat
Appears in
3 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2025-20362

IOC database

Type
cve
Value
CVE-2025-20362
First seen
Last seen
Attached to this threat
Appears in
3 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-20182

IOC database

Type
cve
Value
CVE-2026-20182
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-20316

IOC database

Type
cve
Value
CVE-2026-20316
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2026-20079

IOC database

Type
cve
Value
CVE-2026-20079
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 208.123.119.215 VT 4 / 89

IOC database

Type
ipv4
Value
208.123.119.215
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
CC=US ASN=AS395092 shock hosting llc

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 89 VirusTotal vendors

VendorVerdictDetection
ArcSight Threat Intelligence malicious malware
Fortinet malicious malware
SOCRadar malicious malicious
alphaMountain.ai suspicious suspicious

Details From VirusTotal

Basic Properties
Network208.123.116.0/22
CountryUS
AS ownerShock Hosting LLC
ASN395092
Regional registryARIN
History
Last analysis2026-09-10 23:34 UTC
Last modified on VirusTotal2026-09-10 23:40 UTC
WHOIS record date2026-09-05 13:17 UTC

hash_sha256 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 VT: not in VT

IOC database

Type
hash_sha256
Value
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: not in VT

hash_sha256 b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d VT: not in VT

IOC database

Type
hash_sha256
Value
b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: not in VT

hash_sha256 db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e

IOC database

Type
hash_sha256
Value
db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e

ipv4 91.214.78.118 VT 3 / 89

IOC database

Type
ipv4
Value
91.214.78.118
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 3 of 89 VirusTotal vendors

VendorVerdictDetection
ArcSight Threat Intelligence malicious malware
Fortinet malicious malware
SOCRadar malicious phishing

Details From VirusTotal

Basic Properties
Network91.214.78.0/24
CountryGE
AS ownerMerenyuk Nikita Vladimirovich
ASN200579
Regional registryRIPE NCC
History
Last analysis2026-09-10 23:34 UTC
Last modified on VirusTotal2026-09-11 00:58 UTC
WHOIS record date2026-09-09 20:15 UTC

References (2)

  • reference AlienVaulkt OTX
  • OTX pulse AlienVaulkt OTX

    Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 d

Remediations (8)

  • web:aicybr.com

    Cisco updated its Secure Firewall Management Center (FMC) advisory on September 9, 2026 to confirm active exploitation of CVE-2026-20079, a CVSS 10.0 authentication-bypass vulnerability that can give an unauthenticated remote attacker root access to an affected FMC system.

  • web:arcticwolf.com

    CVE-2026-20316, CVE-2026-20079: Active Exploitation of Cisco Secure Firewall Management Center Zero-Day CVE-2026-20316 is an actively exploited Cisco FMC zero-day that could enable unauthorized access and lead to full system compromise when chained with other vulnerabilities . Review the risks and mitigation steps.

  • web:blog.talosintelligence.com

    Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco's Secure Firewall Management Center (FMC) Software.

  • web:sec.cloudapps.cisco.com

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java ...

  • web:sec.cloudapps.cisco.com

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this ...

  • web:securityarsenal.com

    CISA confirms active exploitation of CVE-2026-20316 in Cisco FMC. Immediate patching and forensic triage required per BOD 26-04.

  • web:socprime.com

    Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information.

  • web:www.bleepingcomputer.com

    Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
0 / 0
IPs scored
1 / 2
Flagged
0