Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has revealed that three distinct threat groups – including state-sponsored actors and ransomware operators – are exploiting vulnerabilities in their Secure Firewall Management Center (FMC) software to steal credentials and deploy ransomware. These attacks leverage multiple vulnerabilities, allowing attackers to gain remote access, deploy web shells, and ultimately install Qilin ransomware.
Cisco has announced that three separate threat clusters are actively exploiting vulnerabilities within their Secure Firewall Management Center (FMC) software. These groups are leveraging two recently patched vulnerabilities to achieve their objectives. The first, CVE-2026-20079 (CVSS score: 10.0), is an authentication bypass in the web interface, enabling unauthenticated remote attackers to execute scripts and gain root access. The second vulnerability, CVE-2026-20316 (CVSS score: 5.3), allows unauthenticated remote login using a low-privilege account to access sensitive data. Both vulnerabilities can be combined with other Cisco Secure FMC vulnerabilities to elevate privileges. Cisco Talos identified these three clusters of post-compromise activity, linked to both state-sponsored and crimeware threat actors. Specifically, UAT-12197 exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor for database queries and credential theft. UAT-11823 exploited both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell, two bash scripts for harvesting managed-device configurations, and a variant of Cyclops Blink, attributed to the Russian state-sponsored hacking group Sandworm. Finally, UAT-11988, a ransomware operation, exploited CVE-2026-20316 for initial access and then utilized legitimate FMC tooling in a living-off-the-land (LotL) attack, conducting reconnaissance, deploying tunneling tools, collecting credentials, building a target list for encryption, and deploying Qilin ransomware. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply patches by September 12, 2026. Cisco advises customers to apply available hotfixes and is preparing a comprehensive hardening release next week.
