VYPR
advisoryPublished Sep 9, 2026· 1 source

Cisco Secure Firewall Management Center Exploited by State-Sponsored Actors and Ransomware Groups

Cisco Talos is tracking active exploitation of two critical vulnerabilities in Cisco Secure Firewall Management Center (FMC) software, enabling root access and credential theft.

Cisco Talos is actively monitoring the exploitation of two significant vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) software. The first, CVE-2026-20079, carries a critical CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and gain root-level access to the underlying operating system by executing scripts on vulnerable devices. The second, CVE-2026-20316, with a CVSS score of 5.3, permits remote attackers to log in using low-privileged accounts, which can be chained with other vulnerabilities to escalate privileges.

These flaws are not theoretical; Cisco Talos has identified in-the-wild abuse by both state-sponsored actors and ransomware operators. The urgency for customers to address these vulnerabilities is paramount. Cisco has provided security advisories and released hotfixes for affected software versions. A comprehensive hardening release incorporating these patches, along with other internally discovered vulnerabilities, is expected the week of September 14th.

Talos's analysis has uncovered three distinct clusters of post-compromise activity on compromised FMC instances. The first cluster, tracked as UAT-12197, involves the exploitation of CVE-2026-20079, leading to the deployment of web shells, a Java Archive (JAR)-based command executor, and the exfiltration of credentials. The attackers utilized a JSP-based web shell to drop a malicious JAR file, which was then used to query internal databases for user authentication data.

The second intrusion cluster, attributed to UAT-11823, also exploited CVE-2026-20079 and CVE-2026-20316. This cluster resulted in the deployment of a Netcat-based reverse shell and proxy tooling. Ultimately, this activity led to the deployment of a variant of the Cyclops Blink malware, a threat previously attributed to the Russian APT Sandworm group by international intelligence agencies.

A third cluster of malicious activity, identified as UAT-11988 and assessed with high confidence to be a ransomware operator, targeted an FMC instance. This actor gained initial access using static credentials (potentially leveraging CVE-2026-20316) and then employed legitimate, built-in FMC tools in a living-off-the-land (LOTL) fashion. This allowed for extensive reconnaissance, deployment of tunneling tools for persistent access, credential harvesting, and the creation of a target list for encryption.

The tactics, techniques, and procedures observed in the third cluster were consistent with those employed by affiliates of the Qilin ransomware. This highlights the dual threat posed by these vulnerabilities, attracting both sophisticated state-sponsored actors and financially motivated cybercriminals.

Given the active exploitation and the critical nature of these vulnerabilities, organizations utilizing Cisco Secure Firewall Management Center are strongly advised to consult Cisco's security advisories and apply the available hotfixes immediately. Failure to do so leaves networks exposed to severe compromise, including data theft, malware deployment, and full system control.

Synthesized by Vypr AI