Ongoing exploitation of Cisco vulnerabilities: hackers drop web shells
CISA has issued an urgent warning to apply patches.

Image by Cybernews.
- Cisco says attackers are exploiting two known Secure Firewall Management Center flaws, including one rated 10 out of 10.
- The critical flaw can let remote attackers bypass login and gain root access to affected systems.
- Cisco saw three attack clusters, including suspected Russian state hackers and a Qilin ransomware operator.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Cisco warns that threat actors are actively exploiting a maximum severity vulnerability in the Secure Firewall Management Center (FMC) that was disclosed and patched earlier this year.
The Cisco Talos threat intelligence team said it is actively tracking 3 clusters actively exploiting 2 vulnerabilities in FMC, a system for central management of Cisco firewalls. Both state-sponsored and criminal hackers are leveraging the bugs.
One of them, tracked as CVE-2026-20079, is critical and carries a severity score of 10 out of 10, allowing attackers to remotely bypass authentication and gain root access.
Cisco released security updates to address this vulnerability in March, warning that there are no other workarounds.
“In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate it,” the updated advisory explains.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
This prompted the US Cybersecurity and Infrastructure Security Agency (CISA) to add the bug to its Known Exploited Vulnerabilities (KEV) catalog, setting a 3-day deadline for federal agencies to apply mitigations.
In July, Cisco also detected active exploitation of a less severe zero-day vulnerability that allows unauthenticated attackers to access sensitive data.
Attackers dropping backdoors
The first attack cluster leverages the critical bug to plant a malicious web shell – a backdoor that lets attackers remotely execute commands through web requests.
The attackers later abused it to place a malicious JAR file to query internal databases and steal user authentication information and credentials.
The second group, which Cisco believes is a Russian advanced persistent threat actor behind Sandworm, uses the flaws to establish reverse shells for control. The threat actor was observed stealing managed device configurations and deploying Cyclops Blink malware.
Check if your data has been leaked
This malware gives attackers persistence and is later used for credential and data theft, arbitrary file and command execution, network scanning and discovery, and packet sniffing.
The third attacker is a ransomware operator. It logs in with static credentials, performs extensive reconnaissance and domain enumeration, steals credentials, and builds a list of target endpoints within the compromised organization for encryption. Malicious activity ultimately leads to the deployment of the Qilin ransomware family.
“Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco,” the report reads.
“A comprehensive hardening release consisting of these hotfixes, along with other internally discovered vulnerabilities, will be released next week (Week of September 14th).”
Eclypsium recently reported on other cyberattacks targeting Cisco firewalls – attackers leverage CVE-2026-20349, a low-barrier denial of service vulnerability, to crash the devices, causing a reboot.