Cisco's Firewall Bug Scored a Perfect 10. Not the Good Kind.

Cisco's Firewall Bug Scored a Perfect 10. Not the Good Kind.

In gymnastics, a perfect 10 gets you a gold medal. In cybersecurity, a perfect 10 means three different hacking crews — including a Russian state-sponsored espionage unit and a ransomware gang — are currently taking turns walking through your firewall's front door like it's not even locked.

Root Access, No Password Required

CVE-2026-20079 is an authentication bypass in Cisco's Firewall Management Center web interface, and it carries a CVSS score of 10.0 — the maximum possible severity. It lets an unauthenticated remote attacker execute script files and land root access on the underlying operating system. No credentials, no phishing email, no "please click this link." Just walk right in.

Researchers have now identified three separate threat clusters exploiting it: UAT-12197 dropping web shells to raid internal databases, UAT-11823 (tied to Russia's Sandworm) deploying the Cyclops Blink implant for long-term espionage, and UAT-11988, a Qilin ransomware affiliate doing reconnaissance and credential theft before detonating ransomware. CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 12 to patch.

When Your Firewall Becomes the Break-In Tool

The bitter irony here is hard to miss: the device meant to keep attackers out is the one being turned into their entry point, staging ground, and getaway car. Firewall management consoles sit at the center of network trust — compromise one and you're not just in, you can see and shape everything the firewall is supposed to protect.

Three unrelated threat actors independently zeroing in on the same hole this fast tells you exploit code is circulating widely and the clock on "patch when convenient" ran out days ago. If FMC is anywhere in your stack, this isn't a maintenance-window item — it's a today item.

A perfect score is great on a report card. On a CVSS scale, it's your cue to stop reading and start patching.

Perimeter security is only as strong as its weakest unpatched box — if you want a second set of eyes on your infrastructure's exposure, James and the team at WTK are happy to talk through where the gaps might be at webtechkitchen.com/contact.

Source: The Hacker News