Cisco Talos has identified active exploitation of two significant vulnerabilities within Cisco Secure Firewall Management Center (FMC) Software. These flaws are being leveraged by state-sponsored hacking groups and a ransomware affiliate to gain root access, deploy malware, and orchestrate attacks on enterprise networks. The FMC acts as a central console for managing multiple Cisco firewalls, making this incident particularly critical for enterprise security. The more severe of the two vulnerabilities, CVE-2026-20079, has been assigned a perfect CVSS score of 10.0. This flaw allows remote attackers to bypass login controls without authentication. The issue arises from an improper system process during the FMC device boot-up, which attackers can hijack if a legitimate user does not claim the session. Although Cisco patched this vulnerability in March 2026, it became aware of its active exploitation in August. The U.S. Cybersecurity and Infrastructure Security Agency has since added it to its Known Exploited Vulnerabilities catalog. The second vulnerability, CVE-2026-20316, involves hard-coded static credentials linked to a low-privileged account. With a CVSS score of 5.3, it allows unauthorized remote logins. While this flaw alone offers limited access, it can escalate privileges when combined with other vulnerabilities. Cisco addressed this issue in July 2026, and it too is listed in the KEV catalog. Talos researchers have identified three clusters of post-compromise activity, each showing different threat actor objectives. The first cluster utilized the authentication bypass to install a web shell for credential theft. The second cluster, linked to the Russian group Sandworm, used both vulnerabilities to deploy Cyclops Blink malware, facilitating extensive data exfiltration and command execution. The third cluster, associated with a Qilin ransomware operator, exploited the static-credential flaw to infiltrate networks and deploy ransomware. Cisco and Talos strongly urge organizations using Secure FMC to immediately apply the available patches for both vulnerabilities. Organizations unable to patch should restrict internet exposure of FMC management interfaces to reduce attack risk. A broader hardening release with additional patches is expected by mid-September.