Cisco FMC CVE-2026-20079 CVSS 10.0: Sandworm deploying Cyclops Blink, Qilin ransomware staging, third cluster dropping web shells, CISA deadline tomorrow September 12      Chrome zero-day seven: seventh actively exploited V8 flaw in 2026 patched Tuesday, CISA KEV, update to 153.0.8020.62 across all platforms      EU Cyber Resilience Act: vulnerability reporting obligations live today, 24-hour ENISA disclosure window now active for software vendors selling into the EU      Cisco FMC CVE-2026-20079 CVSS 10.0: Sandworm deploying Cyclops Blink, Qilin ransomware staging, third cluster dropping web shells, CISA deadline tomorrow September 12      Chrome zero-day seven: seventh actively exploited V8 flaw in 2026 patched Tuesday, CISA KEV, update to 153.0.8020.62 across all platforms      EU Cyber Resilience Act: vulnerability reporting obligations live today, 24-hour ENISA disclosure window now active for software vendors selling into the EU     
CyberSipTM
Intelligence without the noise
Issue No. 128
September 11, 2026
3 items · past 24h
<5 min read
Today's picture

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center that gives unauthenticated attackers root command execution on the centralized console used to manage an entire Cisco firewall estate, with Cisco Talos identifying three distinct exploitation clusters including Sandworm deploying Cyclops Blink for persistent access and a Qilin ransomware affiliate conducting Active Directory reconnaissance before staging encryption, with the CISA KEV federal deadline falling tomorrow September 12. Google patched the seventh Chrome zero-day of 2026 on Tuesday, an actively exploited V8 engine vulnerability also added to CISA KEV the same day. The EU Cyber Resilience Act's vulnerability reporting requirements took effect today, requiring software vendors selling products with digital elements in the EU to report actively exploited vulnerabilities to ENISA within 24 hours of discovery and to notify affected users within 72 hours.

Today's intelligence
3 items
01 CriticalCisco Secure FMCSandworm + Qilin
Cisco FMC CVE-2026-20079: Sandworm is deploying Cyclops Blink through it, Qilin ransomware affiliates are staging through it, federal deadline is tomorrow
Cisco's Secure Firewall Management Center is the single console used to configure, monitor, and push policy to an organization's entire Cisco Firepower and Secure Firewall estate. CVE-2026-20079 bypasses its authentication entirely. Three separate threat clusters have been exploiting it since August. One is Sandworm, deploying a Cyclops Blink variant for long-term visibility into firewall policy and traffic. One is Qilin, conducting domain reconnaissance before ransomware staging. The CISA KEV deadline is September 12.
Auth bypassCVE-2026-20079
CVSS 10.0
Unauthenticated
Root RCE via HTTP
Companion flawCVE-2026-20316
CVSS 5.3
Static credentials
Chained with above
ActorsSandworm (GRU)
Qilin ransomware
Third unattributed
cluster
KEV deadlineSeptember 12, 2026
(tomorrow)
SaaSSCC Firewall Mgmt
patched by Cisco.
On-prem: apply
hotfix manually.
Cisco updated its CVE-2026-20079 advisory on September 9 to confirm active exploitation beginning in August 2026. CVE-2026-20079 stems from an improperly created system process at boot time in Cisco Secure FMC software. Sending crafted HTTP requests to the web interface bypasses the login flow entirely, with no credential to guess, and achieves root-level command execution. CVE-2026-20316, a companion flaw involving hard-coded static credentials rated CVSS 5.3, is being chained with CVE-2026-20079 by some actors to enable additional access paths. Cisco Talos identified three distinct post-compromise clusters. UAT-11823, attributed to Sandworm (Russian GRU), uses both CVEs to establish a reverse shell and deploys Cyclops Blink, the modular router-targeting malware previously attributed to Sandworm by CISA and Five Eyes partners in 2022. An FMC compromise gives Sandworm persistent visibility into an organization's entire firewall policy and traffic flow. UAT-11988, assessed as a Qilin ransomware affiliate, logs in via the static credentials of CVE-2026-20316, uses FMC's own built-in tooling to conduct Active Directory reconnaissance, and stages a SOCKS5 proxy and reverse SSH tunnel before deploying ransomware. A third cluster, UAT-12197, drops a JSP web shell and a malicious JAR file to harvest authentication data. Cisco's cloud-hosted SCC Firewall Management was patched by Cisco before disclosure. On-premises FMC operators must apply the hotfix or a fixed software release manually. There is no workaround. Cisco provides a log indicator for possible exploitation in its advisory.
FMC is the management plane for Cisco's firewall estate. Compromise here is not a single firewall being breached; it is the console from which an attacker can read every firewall rule, every traffic policy, every monitored host, and potentially push configuration changes across the entire managed fleet. Sandworm's goal, persistent visibility into firewall policy and traffic flow, is exactly what you would want if planning future operations against the same organization or its partners. Qilin's use of FMC's own legitimate tooling for AD reconnaissance is the management-plane-as-attack-tool pattern this brief has tracked through N-central (Issue 127), Cisco Nexus (Issue 123), and SonicWall SMA1000 (Issue 123): the platform's legitimate administrative reach becomes the attacker's lateral movement capability.
Cisco's advisory documents a specific log indicator for CVE-2026-20079 exploitation. Organizations that have not yet patched should check for this indicator before applying the hotfix, because the hotfix prevents future exploitation but does not remediate any prior compromise. Sandworm's deployment of Cyclops Blink is the specific finding that warrants treating a potentially exposed FMC as compromised until forensically cleared: Cyclops Blink is persistent malware designed to survive reboots and standard remediation, requiring specific removal procedures documented in CISA's 2022 advisory on the malware family.
  • Apply the Cisco hotfix or a fixed software release for CVE-2026-20079 to all on-premises Cisco Secure FMC instances immediately. The CISA KEV deadline is tomorrow. There is no workaround; the fix is the only remediation. SCC Firewall Management (cloud) was patched by Cisco and requires no action from customers.
  • Before or alongside patching, check Cisco's documented log indicator for CVE-2026-20079 exploitation. If indicators are present, treat the FMC instance as potentially compromised and initiate incident response rather than assuming the patch alone resolves the situation. Engage Cisco TAC for recovery guidance. For any FMC that was internet-accessible before the hotfix, review for web shells, unexpected JAR files, and unusual outbound connections consistent with the three Talos-identified clusters.
No credentials. Root access to the console that manages your entire firewall estate. Sandworm is using it to watch your traffic. Qilin is using it to map your domain before encrypting it. Deadline is tomorrow. Apply the hotfix and check the log indicator before assuming the instance is clean.
02 HighChrome Zero-Day SevenCISA KEV
Chrome's seventh zero-day of 2026 is confirmed exploited in the wild and on CISA KEV — update to 153.0.8020.62 now
Google patched 230 vulnerabilities in Tuesday's Chrome release, including an actively exploited V8 engine type confusion zero-day added to CISA KEV the same day. The fix is in Chrome 153.0.8020.62. This is the seventh in-the-wild Chrome zero-day fixed in 2026, approximately one every five to six weeks. Enterprise environments should push the update via managed policy rather than waiting for staged rollout.
Fixed inChrome 153.0.8020.62
All platforms
TypeV8 type confusion
Actively exploited
KEVAdded same day
as patch release
2026 count7th Chrome
zero-day in 2026
Google released Chrome 153.0.8020.62 on Tuesday September 9, patching 230 vulnerabilities including a V8 JavaScript engine type confusion flaw confirmed exploited in the wild. CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day. V8 type confusion flaws allow a crafted web page to trigger memory corruption in Chrome's JavaScript engine, enabling arbitrary code execution inside the browser's renderer process. This is the seventh Chrome zero-day confirmed exploited in 2026, following six others addressed between January and September including the V8 type confusion CVE-2026-85046 from Issue 125. The current pace is roughly one actively exploited Chrome zero-day every five to six weeks.
Seven confirmed in-the-wild Chrome zero-days in under nine months reflects sustained attacker investment in browser exploitation as an initial access vector. Drive-by compromise through a browser zero-day requires only that the target visit a malicious or compromised page; no phishing click, no attachment, no credential entry. At one confirmed Chrome zero-day every five weeks, treating Chrome updates as routine monthly patching rather than emergency deployment misaligns the defensive posture with the actual attack tempo.
  • Update Chrome to 153.0.8020.62 or higher across all endpoints. Individual users can trigger an immediate update at chrome://settings/help. Enterprise administrators should push the update via managed policy rather than relying on Chrome's staged rollout to reach all endpoints within the urgency window that CISA KEV implies.
Seven Chrome zero-days in nine months. This one is confirmed exploited and on CISA KEV. Update to 153.0.8020.62. Push it via managed policy in enterprise environments; staged rollout is too slow for a confirmed in-the-wild exploit.
03 EU Cyber Resilience ActEffective Today
The EU Cyber Resilience Act's vulnerability reporting obligations are live today: 24 hours to notify ENISA, 72 hours to notify users
The CRA's vulnerability reporting requirements took effect September 11, 2026. Any software vendor selling a product with digital elements into the EU market must now report actively exploited vulnerabilities to ENISA within 24 hours of discovery and notify affected users within 72 hours. This applies regardless of where the vendor is headquartered. The coordination obligations between the 24-hour ENISA report and the 72-hour user notification create a new operational workflow that most software security teams do not yet have in place.
EffectiveSeptember 11, 2026
(today)
ENISA deadline24 hours from
discovery of an
actively exploited
vulnerability
User notification72 hours from
discovery
ScopeAll software vendors
selling products with
digital elements
into the EU market
The vulnerability reporting provisions of the EU Cyber Resilience Act took effect today. The CRA requires manufacturers of products with digital elements sold in the EU to report any actively exploited vulnerability in their product to ENISA within 24 hours of becoming aware of it. A separate 72-hour window requires notification to affected users. The obligations apply to any vendor selling into the EU market regardless of where the company is based, meaning US, UK, and Asian software vendors with EU sales are in scope. The 24-hour ENISA reporting window runs parallel to the 72-hour user notification window; they are separate obligations with separate deadlines and separate content requirements. The reporting is made through ENISA's Single Reporting Platform. Penalties for non-compliance can reach 2.5% of global annual turnover or 15 million euros, whichever is higher, for manufacturers found in serious non-compliance.
The 24-hour ENISA disclosure window is tighter than any existing mandatory vulnerability reporting framework and arrives before most organizations have completed internal triage, let alone coordinated disclosure with researchers or partners. For software vendors selling into the EU, today marks the start of a new operational obligation that requires a documented incident-response workflow specifically for actively exploited vulnerabilities: who decides "actively exploited" has been confirmed, who files the ENISA report, and how that report is coordinated with the separate 72-hour customer notification. Organizations that have not built that workflow yet are operating out of compliance from today.
  • Software vendors with EU market exposure should verify whether a documented CRA vulnerability reporting workflow exists and is operational. The workflow must include a defined trigger for what constitutes "actively exploited" (ENISA's guidance uses the same definition as CISA KEV), a designated responsible party for filing via ENISA's Single Reporting Platform, and a separate 72-hour customer notification path. If no workflow exists, the current non-compliance risk is active.
  • Security teams that receive vulnerability reports from external researchers should assess whether those reports describe active exploitation. If they do, the 24-hour ENISA clock starts from the moment the manufacturer becomes aware of the exploitation, not from when they finish analysis. Building a rapid triage step specifically for exploitation status into the inbound vulnerability intake process is the operational adjustment the CRA requires.
The 24-hour ENISA window is live. It runs from the moment you become aware of active exploitation, not from when you finish your internal investigation. If you sell software into the EU and do not have a documented CRA reporting workflow today, you are non-compliant as of this morning. The fine ceiling is 2.5% of global annual turnover.
Cross-source standouts
01
The management plane pattern: Cisco FMC joins N-central, Nexus 9000, and SonicWall SMA1000 as the week's third management-layer target
Three of this week's four leading stories have been management-layer attacks. N-central (Issue 127) is the MSP management platform. Cisco FMC (today) is the firewall management platform. Cisco Nexus 9000 CVE-2026-20212 (Issue 123) was root RCE on the data center switch fabric, and SonicWall SMA1000 (Issue 123) was the SSL VPN management interface. The pattern reflects a strategic shift that security researchers documented in early 2026: as endpoint defenses improve, attackers are targeting the management infrastructure that sits above endpoints because it provides wider reach with less detection. An attacker on a management platform inherits the platform's legitimate administrative authority over everything it manages. The Qilin cluster using FMC's own built-in tooling for AD reconnaissance is the clearest illustration: the attacker did not bring custom tools, they used the same FMC features the legitimate administrator uses. That behavior is extremely difficult to distinguish from normal administrative activity in log analysis.
02
CRA's 24-hour window and the coordinated disclosure tension: what happens when the exploitation clock starts before the patch is ready
The CRA's 24-hour ENISA reporting obligation for actively exploited vulnerabilities creates a structural conflict with standard coordinated disclosure practice, in which vendors typically work with researchers to develop a patch before public disclosure. Under coordinated disclosure, a vendor learning about a vulnerability being actively exploited would normally accelerate patch development while preparing a disclosure advisory. Under the CRA, that same vendor must also file with ENISA within 24 hours. ENISA receiving early notification of an actively exploited vulnerability before a patch exists creates a regulatory disclosure before the vendor's remediation is ready. The practical question is whether ENISA will hold filings confidential until patches are available or whether the disclosure pathway from vendor to ENISA could itself become a channel through which exploitation details spread. ENISA's guidance indicates filings are not automatically public, but the framework for how the 24-hour reports are used operationally is still being established. Software security teams navigating the first CRA-triggered reports should document the timeline of when exploitation was confirmed, when ENISA was notified, and when user notification was sent, both for compliance evidence and for understanding how the new framework operates in practice.
Still watching
Days 2–7+
ShieldCrash (ShieldBreak bypass) (Issue 126 · Nightmare Eclipse, no CVE, arbitrary file read as SYSTEM on latest patched Windows) — ShieldBreak CVE-2026-69414 is patched. ShieldCrash is not. Monitor MSRC for advisory and apply immediately. Keep behavioral detection for the series active.
Day 3
SAP OVERPASS CVE-2026-44756 (Issue 126 · CVSS 10.0, unauthenticated SAP kernel EPP RCE) — apply patch per SAP Note 3500180. Restrict EPP endpoint to authorized networks. No exploitation confirmed yet; prior CVSS 10.0 SAP flaws moved to exploitation within days of disclosure.
Day 3
StyleSmuggler CVE-2026-75650 (Issue 125 · CVSS 10.0, Magento/Adobe Commerce, actively exploited since September 4) — apply composer patch VULN-39341. Rotate encryption key and all derived credentials including payment gateway API keys. Run eComscan for the Linux backdoor.
Day 7+
GitLab CVE-2026-19478 (Issues 111/114 · confirmed exploited, no patch for 18.2–18.10 through mid-November 2026) — restrict /api/graphql. Hunt @gl_introduced in web logs. Patch available for 19.x and 18.11+ branches only.
Day 7+