Skip to main content
Security

Cisco says three threat clusters exploiting Secure Firewall Management Center flaws

Cisco says three threat clusters exploiting Secure Firewall Management Center flaws Image: Primary
Cisco Talos said three clusters of post-compromise activity have exploited two recently patched Secure Firewall Management Center vulnerabilities. CVE-2026-20079, rated CVSS 10.0, is an authentication bypass in the FMC web interface that can let an unauthenticated remote attacker run script files and gain root on the underlying operating system. UAT-12197 used it to deploy JSP web shells and a Java command executor to pull authentication data and credentials. UAT-11823 chained both flaws to deliver a reverse shell, configuration-harvesting scripts and a Cyclops Blink variant previously attributed to Sandworm. UAT-11988 used CVE-2026-20316 for initial access, then living-off-the-land tooling to reconnoiter, tunnel, collect credentials and deploy Qilin ransomware. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, with federal patch deadline of September 12, 2026.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

NASA and IBM release open lunar foundation model on Hugging Face

NASA and IBM Research released the NASA-IBM Lunar Foundation Model, an open-source AI model built for lunar science, hosted publicly on Hugging Face with its codebase on GitHub. NASA said the model was trained primarily on 17 yea...

Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...