Cisco confirmed on September 9 that attackers are exploiting a CVSS 10.0 bypass in its Firewall Management Center to run code as root. CISA added it to its Known Exploited Vulnerabilities list the same day, with a three-day deadline for federal agencies.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence64
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
ESET found the bait comment in a loader for MATCHBOIL, malware it ties exclusively to the Russia-aligned group that feeds targets to Sandworm. The trick works because a model that refuses to read a file returns no verdict at all.
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives40
- Confidence60
A media consortium and DomainTools worked through more than 2,000 records from a Moscow engineering department that appears on no public org chart, and found roughly 250 students on a documented path into Russian military intelligence.
Perspective Coverage
3 publishers
- Builder
- Builder 25%
- Operator
- Operator 65%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
CVE-2026-20079 hands unauthenticated attackers root on Secure Firewall Management Center. CISA wants federal boxes fixed by September 12. The hot fix closes the path but does not evict anyone who already walked it.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 65%
- Investor
- Investor 12%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence74
Eclypsium tracked 158 infrastructure advisories between August 25 and September 17. The exploited maximum-severity flaws it highlights are authentication bypasses in Cisco's Firewall Management Center and Identity Services Engine.
Reality
- Evidence62
- Adoption72
- Hype gap+14
- Incentives65
- Confidence58
Cisco Talos says three separate clusters, one sharing tooling with Sandworm, worked the same CVSS 10.0 bypass in Secure Firewall Management Center. The scope change in that vector reaches every firewall the console manages.
Reality
- Evidence72
- Adoption61
- Hype gap+8
- Incentives38
- Confidence68
Cisco patched CVE-2026-20079 in March 2026 and confirmed in September that attackers had used it in August. Talos ties three clusters to the console, including one it links to Sandworm tooling and a Qilin affiliate.
Reality
- Evidence74
- Adoption72
- Hype gap+5
- Incentives38
- Confidence62
An authentication bypass in Cisco's firewall management console was fixed in March 2026 and exploited in the wild by August. Cisco Talos attributes the activity to three separate clusters with three different objectives.
Reality
- Evidence58
- Adoption55
- Hype gap+14
- Incentives45
- Confidence55
Sophos found the timezone_check implant on compromised Cisco Firewall Management Center devices in August 2026 and assessed it likely Sandworm's work. Generic SysV persistence replaces the firmware trick and widens the appliances it can run on.
Reality
- Evidence63
- Adoption38
- Hype gap+12
- Incentives55
- Confidence58
A wind-farm FortiGate and a Teltonika router put intruders onto a DSO-managed APN, where a WAGO controller with default credentials was waiting. A steam turbine stopped.
Reality
- Evidence66
- Adoption42
- Hype gap+10
- Incentives28
- Confidence58