Skip to main content

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

0
Critical
Vulnerabilityciscoransomware
Published: 09/10/2026 (09/10/2026, 15:43:58 UTC)
Source: Bleeping Computer

Description

Two recently patched vulnerabilities in Cisco Secure Firewall Management Center (FMC) have been exploited by multiple threat clusters linked to ransomware and state-sponsored attacks. CVE-2026-20079 is a critical authentication bypass vulnerability with a CVSS score of 10.0, allowing unauthenticated remote root access. CVE-2026-20316 involves static credentials for a low-privileged account and has a CVSS score of 5.3 but can be combined with other flaws for privilege escalation. Exploitation has led to deployment of web shells, credential theft, reverse shells, proxies, and malware including Qilin ransomware and Cyclops Blink backdoor. Cisco has released hotfixes for both vulnerabilities and plans further hardening patches. The attacks highlight significant post-compromise activity by ransomware affiliates and a Russian state-sponsored group known as Sandworm.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 15:48:59 UTC

Technical Analysis

Cisco Talos reported exploitation of two Secure FMC vulnerabilities: CVE-2026-20079 (authentication bypass, CVSS 10.0) and CVE-2026-20316 (static credentials, CVSS 5.3). Three threat clusters (UAT-12197, UAT-11823, UAT-11988) used compromised FMC devices for reconnaissance, credential theft, and malware deployment. The Qilin ransomware group exploited CVE-2026-20316 to gather extensive network data and deploy ransomware. The Sandworm-linked cluster exploited both vulnerabilities to establish persistent backdoors using a malicious license.tmp file and deployed Cyclops Blink malware. Another cluster deployed a JSP web shell and malicious JAR to steal authentication data. Cisco has issued hotfixes and is releasing additional patches for comprehensive hardening.

Potential Impact

Exploitation allows unauthenticated remote attackers to bypass authentication and execute commands as root on FMC devices, leading to full compromise. Attackers have used these vulnerabilities to deploy ransomware (Qilin), advanced persistent threat malware (Cyclops Blink), steal credentials, and maintain persistent access. The impact includes network reconnaissance, credential theft, lateral movement, and encryption of endpoint files. These attacks have been linked to both criminal ransomware groups and state-sponsored actors, increasing the risk to organizations using affected FMC versions.

Mitigation Recommendations

Cisco has released hotfixes addressing both CVE-2026-20079 and CVE-2026-20316 and urges immediate installation of these patches. Additional comprehensive hardening patches are planned for release soon. Organizations should apply these official fixes promptly to prevent exploitation. No further mitigation recommendations are provided beyond applying Cisco's hotfixes and upcoming patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.71,"severitySource":"heuristic","classifier":"rss-v2"}

Threat ID: 6aa2d1648744ddd5a6dab4d4

Added to database: 09/10/2026, 15:48:52 UTC

Last enriched: 09/10/2026, 15:48:59 UTC

Last updated: 09/10/2026, 16:36:21 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses