If your organisation runs Cisco Secure Firewall Management Center (FMC), you need to stop and read this. Right now, one of the world's most dangerous state-sponsored hacking groups is actively chaining two Cisco vulnerabilities to seize control of enterprise network management infrastructure — and the window to act is already closing. This is not a theoretical threat. It is happening in the wild, confirmed by Cisco Talos, Sophos, and CISA, and it demands an immediate response from every network security team on the planet.


Who Is Sandworm — and Why Should You Be Worried?

Sandworm is a modular botnet and backdoor operator that US and UK government agencies have previously linked to Russia's Main Intelligence Directorate (GRU).

Also tracked as

APT44, VOODOO BEAR, IRON VIKING, Seashell Blizzard, and more than a dozen other aliases

, this group has a long and destructive history.

The threat group is responsible for several high-profile cyberattacks, including the destructive NotPetya cyberattack that targeted hundreds of firms and hospitals worldwide.

Unlike a typical APT focused on espionage, the distinguishing feature of Sandworm is its ability to sabotage at scale. Their campaigns illustrate that cyber capabilities can disrupt and incapacitate nations, economies, and serve as a strategic extension of force in warfare.

This is not a group that simply steals data and disappears quietly. When Sandworm gains a foothold in network infrastructure, the consequences can be catastrophic — and right now, they have found a particularly powerful entry point.


The Vulnerability Chain: CVE-2026-20079 and CVE-2026-20316 Explained

Sandworm is chaining two Cisco Firewall Management Center (FMC) vulnerabilities — a critical authentication bypass (CVE-2026-20079) and a lower-severity credential flaw (CVE-2026-20316) — to deploy an upgraded version of the Cyclops Blink botnet malware.

Understanding how these two flaws work together is key to grasping the severity of this threat:

This authentication bypass vulnerability is due to an improper system process that is created at boot time, and allows remote, unauthenticated attackers to execute scripts and commands that allow root access to the device by simply sending specially crafted HTTP requests to an unpatched device.

A separate, medium-severity flaw involving static, hard-coded credentials in the FMC web interface. On its own it grants limited privileges, but attackers can chain it with CVE-2026-20079 to escalate to full root access.

Cisco Secure FMC is the centralized console administrators use to configure, monitor, and push policy changes to Cisco Firepower firewalls across an organisation's network

— meaning that root-level access to the FMC is effectively master-key access to your entire firewall estate.

Active exploitation of CVE-2026-20316 was confirmed in July 2026, and CISA added it to the KEV catalog on July 29, 2026, weeks before CVE-2026-20079 joined the same list. That gap matters for the timeline: attackers had a working, lower-severity entry point into FMC devices for more than a month before the more dangerous authentication bypass was confirmed as exploited too.


The attack is surgical, fast, and deeply concerning in its sophistication.

Threat actors possibly tied to Sandworm are chaining the two flaws to first download a Netcat-based reverse shell and proxy tool on vulnerable FMC systems and then use that to deploy the new Cyclops Blink variant.

Once inside, the impact escalates rapidly.

The attack chain follows a consistent pattern: upon bypassing authentication, the attacker gains root access to the FMC, deploys a JSP web shell into the CSM Tomcat webroot, and then executes a command to directly exfiltrate user credentials from the database.

The threat actor also uses two Bash scripts to harvest managed-device configurations, which are then put into archives for exfiltration. Additionally, it downloads a modular ELF implant — a variant of the Sandworm-linked Cyclops Blink — from its C2 server. The malware is capable of establishing persistence, harvesting credentials, scanning networks, executing commands, transferring files, resolving IP addresses through DNS-over-HTTPS, and sniffing network traffic.

This is not a smash-and-grab operation. This is long-term, persistent access with full visibility into your network.


Cyclops Blink is malware that first surfaced in 2022 and initially targeted WatchGuard firewalls and, later, ASUS devices.

But the 2026 variant is a significant evolution.

The most significant change is that the malware now runs on 64-bit x86-64 Linux systems rather than the older 32-bit PowerPC architecture used by the original version. It also uses generic Linux persistence techniques instead of modifying vendor-specific firmware.

The new Cyclops Blink variant adds active network scanning and packet-capture capabilities and expands its data-collection functions to include password hashes, process command lines, CPU information, and configuration data. These changes potentially make Cyclops Blink compatible with a broader range of Linux-based network appliances and give attackers a more powerful platform for reconnaissance and intelligence collection.

The renewed framework is not simply a persistence implant. On a compromised management-plane appliance, Cyclops Blink can become an internal reconnaissance platform, a selective network-surveillance sensor, and a staging point for broader Sandworm-linked operations.


Three Threat Clusters, One Vulnerability: The Wider Threat Landscape

Sandworm is not the only group exploiting these flaws. The same vulnerabilities are being weaponised by multiple actors simultaneously, making this a multi-front crisis.

A group possibly tied to Sandworm is deploying an upgraded Cyclops Blink botnet; a cluster tracked as UAT-12197 is exploiting CVE-2026-20079 to plant web shells and a Java-based credential-stealing tool; and UAT-11988 is exploiting CVE-2026-20316 to distribute Qilin ransomware.

This flaw was added to the CISA Known Exploited Vulnerabilities catalog, with a federal remediation deadline of September 12, 2026.

If you're not a US federal agency, that deadline should still act as your internal benchmark. The threat is global, the exploitation is active, and every day without patching is a day of unacceptable risk.


Practical Tips: What Your Security Team Should Do Right Now

The good news is that Cisco has released hotfixes and there are concrete, actionable steps every network security team can take today. Here's your immediate action list:

  1. Apply the hotfixes immediately.

Cisco has released hotfixes for release branches 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Administrators should confirm their running version and apply the corresponding hotfix immediately.

Do not wait for a scheduled maintenance window.

  1. Restrict FMC management interface access.

Restrict access to the FMC management interface (UI/API/CLI) using firewall or ACL rules.

The management plane should never be reachable from the open internet.

  1. Hunt for indicators of compromise.

Organisations should immediately apply Cisco's available hotfixes, inspect FMC devices for anomalous SysV services and the timezone_check paths, review outbound TLS sessions on ports 43856 and 49172, and hunt for raw-socket scanning, unusual internal probes, and suspicious packet-capture behaviour.

  1. Rotate all credentials on affected appliances.

At a minimum, organisations should rotate every user credential, key, and certificate stored on the affected appliance.

  1. Don't just patch — investigate.

Remediation should include both patching and incident response because installing the update does not invalidate secrets that may already have been exposed.

  1. Monitor CISA and Cisco advisories continuously.

Monitor Cisco's security portal and CISA KEV listings for updates or additional advisories,

as the threat landscape around these vulnerabilities continues to evolve.

  1. Conduct a broader edge-device audit. This attack is a reminder that network edge and management-plane devices are high-value targets. Audit all internet-facing management interfaces across your entire security stack — not just Cisco FMC.

Conclusion: Complacency Is Not an Option

The Sandworm Cisco FMC campaign is a defining moment for network security teams in 2026. A maximum-severity, zero-credential-required authentication bypass, chained with a hard-coded credential flaw, is being actively exploited by a nation-state actor with a documented history of causing billions of dollars in global damage — and they're using your firewall management platform as the entry point.

Cisco states there is no workaround that fully addresses CVE-2026-20079

, which means patching is the only real answer. The threat is real, the exploitation is confirmed, and the attackers are not waiting.

Is your FMC patched and your management interface locked down? If you're not 100% certain, your network security posture is at risk today. Contact your security operations team or a trusted managed security services provider immediately to audit your Cisco Firewall Management Center deployment, apply the relevant hotfixes, and conduct a full threat hunt for signs of compromise. The cost of acting now is infinitely smaller than the cost of discovering Cyclops Blink already running silently inside your network.