Skip to content

Security1 publisher2 min readPublished

Nation-state and financially-motivated attackers are exploiting the same Cisco FMC authentication bypass

Two actor classes are using CVE-2026-20079 against the console that manages every Cisco Secure Firewall behind it. The same week brought a Linux rootkit planted on F5 BIG-IP APM appliances, with the installation route unreported.

The Watch · Security desk

Illustration accompanying Nation-state and financially-motivated attackers are exploiting the same Cisco FMC authentication bypass

What happened

  • The same roundup item names two Cisco FMC flaws under exploitation, CVE-2026-20079 and CVE-2026-20316, and details only the authentication bypass.
  • A Linux rootkit was deployed on F5 BIG-IP APM devices, according to the same week in review, which does not give the installation vector or a device count.
  • Microsoft's September 2026 Patch Tuesday shipped a record number of fixes, two of them for vulnerabilities already exploited as zero-days.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An attacker past FMC authentication holds the policy console for every Cisco Secure Firewall it manages, so the reachable estate is larger than the one appliance that was breached.
  • constraint A rootkit on an appliance turns remediation into inspection or rebuild, so the FMC and BIG-IP work cannot be closed out by a patch ticket.
  • decision A record Microsoft month with two exploited zero-days competes for the same engineering hours as appliance hunting, and someone has to sequence the two.

The pairing on CVE-2026-20079 carries more weight than its severity label. Help Net Security reports state-sponsored and financially motivated attackers both exploiting the bug, a critical authentication bypass in Cisco Secure Firewall Management Center [1]. Two actor classes working one flaw inside the same reporting window usually means the exploit is cheap to reproduce from the advisory, or already trading.

FMC centrally manages multiple Cisco Secure Firewall devices across a network [2]. An unauthenticated attacker on that console can read and change the rules for everything behind it. The same roundup item names a second FMC flaw, CVE-2026-20316 [4].

The F5 item is the persistence half. A Linux rootkit was deployed on BIG-IP APM devices, according to the same week in review [3]. The roundup does not give an installation vector or a device count [10]. The word rootkit already settles the remediation question: a vendor patch removes the vulnerability and leaves code that is already resident. Remediation on those boxes is an inspection-and-rebuild decision, and the patch is step one.

Patch capacity is contested this month. Microsoft's September 2026 Patch Tuesday shipped a record number of fixes, including for two vulnerabilities exploited as zero-days [5]. Appliance hunting and a record Windows month want the same engineers in the same week.

Two other items from the week need no hunting yet. Calif discovered, weaponized and privately reported to Tencent the WeChat flaw behind "WeWorm", which spreads through WeChat calls with no user interaction [6]. Roughly 67,000 more SatoshiLabs customers had names, email addresses, phone numbers and shipping addresses exposed through a shipping-partner breach, and are getting phishing calls and letters [7]. For wallet holders that is a fraud-awareness problem.

Hunting an appliance is human work this year. Gartner projects that by 2028, 70% of large SOCs will pilot AI agents and 15% will see measurable gains without structured evaluation [8]. The ratio between those two figures is about one pilot in five [9].

What to watch

  • Whether Cisco or CISA publishes exploitation indicators for FMC, and whether CVE-2026-20316 is confirmed as chained to CVE-2026-20079.
  • Whether F5 publishes the rootkit's installation vector and an affected-version list for BIG-IP APM.
  • Whether the groups behind the FMC exploitation get named, which would show whether one exploit is being shared or sold.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories