Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account.
According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.
"Talos' analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors," Cisco Talos said.
The company is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988.
CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.
CVE-2026-20316 has a CVSS score of 5.3 and allows attackers to log in to FMC using static credentials for a low-privileged account. However, Cisco rates the flaw as High severity because it can be combined with other FMC vulnerabilities to elevate privileges.
Cisco has already released hot fixes for both vulnerabilities and is urging customers to install them immediately. The company is also releasing a more comprehensive hardening that includes patches for additional vulnerabilities next week.
Qilin ransomware deployed after FMC breach
Talos attributed one of the intrusion clusters, tracked as UAT-11988, with high confidence to Qilin ransomware affiliates.
The threat actor accessed an FMC device using static credentials associated with CVE-2026-20316, then abused legitimate built-in FMC tools to perform reconnaissance of the victim's network.
The attackers collected hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.
Talos says the collected information was staged in publicly accessible files on the compromised FMC server and downloaded using HTTP GET requests.
The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.
After reconnaissance, the threat actor used post-exploitation tools including Impacket, Invoke-TheHash, and custom EDR killers.
Ultimately, the attackers deployed Qilin ransomware on endpoints to encrypt files.
APT hackers deploy Cyclops Blink
A second intrusion cluster, tracked as UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tooling overlaps with the Sandworm APT group.
Sandworm is a Russian state-sponsored hacking group linked to the Russia's military intelligence agency, GRU, and is known for conducting destructive cyberattacks against governments and critical infrastructure.
The attackers gained access to FMC devices either by exploiting CVE-2026-20079 or using the static credentials associated with CVE-2026-20316.
After gaining access, the threat actors modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure. The malicious license file was then executed as root using Cisco's legitimate package_info.pl utility.
Talos says it believes UAT-11823 exploited both CVE-2026-20079 and CVE-2026-20316 during the attacks.
The attackers also deployed scripts that collected configuration data from managed devices and stored it in archives for later exfiltration.
UAT-11823 ultimately deployed a variant of Cyclops Blink on compromised devices, a modular Linux malware family previously attributed to the Russian Sandworm threat group.
The Cyclops Blink variant acts as a backdoor, providing persistent access, credential theft, and the ability to sniff network traffic.
Third cluster steals credentials
The third cluster, tracked as UAT-12197, exploited CVE-2026-20079 and deployed a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory.
The web shell was then used to install a malicious JAR file named cmd.jar, which allowed them to execute commands on the server.
The attackers used this JAR file to query internal databases on compromised systems and steal user authentication data and credentials.
Confirms link between July attacks
The Talos report also answered ongoing questions about the exploitation of the two vulnerabilities first disclosed in July.
As BleepingComputer reported on July 29, Cisco disclosed that CVE-2026-20316 was being actively exploited and warned that it could be chained with other FMC vulnerabilities to elevate privileges.
At the same time, Cisco updated its advisory for CVE-2026-20079 with the same /var/tmp/license.tmp indicator of compromise used for CVE-2026-20316, but did not confirm that the authentication bypass flaw was also being exploited.
BleepingComputer contacted Cisco at the time to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 was also being exploited, and why the same indicator appeared in both advisories.
Cisco did not answer those questions directly, instead just sharing a statement urging customers to install the hotfixes as soon as possible.
Talos has now confirmed that UAT-11823 exploited both vulnerabilities and used the malicious license.tmp mechanism during its attacks.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)