What happened
CISA's September 9 alert added four entries to the KEV catalog: Cisco Firewall Management Center CVE-2026-20079, Fortinet CVE-2025-25249, Citrix NetScaler CVE-2026-19490 (covered in our NetScaler post) and a Chrome V8 bug that does not concern servers. This post covers the Cisco and Fortinet entries. Both are old patches with new exploitation, which is the pattern that catches teams who treated the original advisory as "we will get to it."
Cisco Secure FMC: CVE-2026-20079
Cisco first published advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 on March 4,
2026. The flaw is in the FMC web interface: a system process created improperly at boot lets an
unauthenticated attacker send crafted HTTP requests, bypass authentication and run script files
as root. Cisco scores it 10.0 (CVSS 3.1, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The
advisory now says: "In August 2026, the Cisco PSIRT became aware of active exploitation of this
vulnerability." BleepingComputer reports log evidence of possible exploitation as early as July
23.
On September 9 Cisco Talos described three clusters of post-compromise activity on FMC instances:
- UAT-12197 deployed a JSP web shell and a Java command executor to pull authentication data from the FMC's internal database. Talos has not tied it to a named group.
- UAT-11823 used CVE-2026-20079 together with CVE-2026-20316 (a static credential flaw in FMC that CISA added to the KEV in July) to open reverse shells, collect configuration and install the Cyclops Blink implant. Talos links it to the Russian state-sponsored group Sandworm with high confidence.
- UAT-11988 used CVE-2026-20316 for initial access, set up SOCKS5 and reverse SSH tunnels and delivered Qilin ransomware to selected systems. Talos assesses with high confidence that it is a ransomware operator.
Fixed releases are 7.0.10 (for 7.0 and earlier), 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0. Cisco says there are no workarounds. The SaaS-delivered Security Cloud Control Firewall Management has already been fixed by Cisco. Upgrading prevents future exploitation but does not clean an FMC that was already compromised, and Cisco asks affected customers to contact TAC.
Fortinet: CVE-2025-25249
Fortinet published FG-IR-25-084
on January 13, 2026: a heap-based buffer overflow in the cw_acd daemon of FortiOS and
FortiSwitchManager that "may allow a remote unauthenticated attacker to execute arbitrary code or
commands via specifically crafted requests." cw_acd handles CAPWAP, the protocol
FortiGates use to manage FortiAP access points, on UDP 5246 and above. Fortinet lists two
workarounds: remove fabric from the interface's allowaccess setting, or
block CAPWAP-CONTROL (ports 5246 to 5249) with a local-in policy.
The severity depends on who you ask. Fortinet's advisory page scores it 7.4, Fortinet's CNA record in NVD says 8.1, and NIST's own assessment is 9.8. The Hacker News reported 7.3. We use the vendor advisory's number above, but the difference matters less than the fact that it is exploited and needs no credentials.
The exploitation was reported by SOCRadar and covered by SecurityWeek on September 10. It installs PivotC2, a Node.js remote access trojan built for FortiGate post-exploitation that gives the attacker a shell, traffic tunnelling, network scanning and configuration harvesting. Activity goes back to at least July 2026. SecurityWeek quotes SOCRadar as saying attackers "targeted more than 30,000 IP addresses," infecting 178 devices; The Hacker News reported more than 3,000 targeted addresses. The 178 figure is consistent across reports. Most victims were in the US, at least two intrusions led to data theft, and SOCRadar assesses the actor as "likely" Russian-speaking cybercriminals. That attribution is SOCRadar's, not Fortinet's. At the time of writing Fortinet's advisory still said the flaw was not known to be exploited.
Why it matters if you run public infrastructure
A firewall manager and a firewall are the two devices you least want an attacker to own. The FMC holds the policy and credentials for every Firepower device it manages; one of the Talos clusters went straight for its user database. A FortiGate sits in the path of all traffic, and PivotC2 is designed to turn it into a pivot point. In both cases the vendor had a fix out months before the attacks began: January for Fortinet, March for Cisco. Exploitation of old, known bugs on edge devices is the normal case in the KEV catalog, not the exception, which is why the question "is this management interface reachable from the internet at all" pays off more often than any single patch.
What to check this week
- Find every FMC web interface you expose. It should not be reachable from the internet. If it is, restrict it to a management network now, then upgrade to the fixed release for your train.
- Look for FMC compromise before and after patching. Cisco's advisory gives
an expert-mode check:
zgrep "package_info.*license" /var/log/messages*, looking for references to/var/tmp/license.tmp. Talos publishes hashes, IP addresses and Snort rules (SIDs 66075 to 66080 for this CVE). Also confirm the CVE-2026-20316 fix from July is installed, since two clusters used it. - Upgrade FortiOS to 7.6.4, 7.4.9, 7.2.12 or 7.0.18 or later, and FortiSwitchManager to 7.2.7 or 7.0.6. FortiOS 6.4 gets no fix, so plan a migration.
- If you cannot upgrade a FortiGate today, remove
fabricaccess from WAN interfaces or block UDP 5246 to 5249 with a local-in policy. CAPWAP has no reason to be open on an internet-facing interface in most deployments. - Hunt for PivotC2 on FortiGates. Unexpected Node.js processes, unknown admin accounts, and configuration exports you did not make are the signs to look for; SOCRadar's report has the indicators.
How Attack Surface Scan covers this
For the two products the answer is different.
Cisco FMC is not in the product catalog our vulnerability matching recognizes, so we will not raise a CVE finding for CVE-2026-20079. What we do show is that a host under your verified domains answers on 443 or another web port we check, the certificate it presents, and an alert when a new login page appears. That tells you where an exposed management interface is; the version check has to happen on the FMC.
FortiOS is in the catalog, recognized by its SSL-VPN login page. FortiGates do
not publish their firmware version to anonymous visitors, so when we see that page we raise KEV
CVEs such as this one as potential matches, capped at medium severity and tagged
potential, with instructions for checking the real version. Two limits apply. We only
recognize a FortiGate that serves the SSL-VPN portal on a web port; one that exposes only CAPWAP is
invisible to us, because we do not scan UDP 5246 (see Exposed
services for the ports we check). And we never test the overflow or attempt exploitation. See
Vulnerability matching for how matches, potential matches and
KEV prioritisation work.
Sources
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog (September 9, 2026)
- Cisco: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability (cisco-sa-onprem-fmc-authbypass-5JPp45V2)
- Cisco Talos: Active exploitation of Cisco Secure Firewall Management Center
- Fortinet PSIRT: FG-IR-25-084, Heap-based buffer overflow in cw_acd daemon
- NVD: CVE-2025-25249
- BleepingComputer: Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
- The Hacker News: Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
- SecurityWeek: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
- The Hacker News: CISA Flags Exploited Cisco, Citrix, Fortinet Flaws