Cisco Secure FMC/CSM cmd.jar Web Shell Artifact (CVE-2026-20079/UAT-12197)
Detects attempts to access or execute a file named 'cmd.jar' within the Cisco Firepower Management Center (FMC) or Cisco Security Manager (CSM) environment. This filename is associated with web shell activities used for unauthorized command execution on vulnerable Cisco appliances.
Suricata

