LmCast :: Stay tuned in

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Recorded: Sept. 10, 2026, 4 p.m.

Original Summarized

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

IDScan confirms breach tied to 153 million stolen driver’s licenses

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

By Lawrence Abrams

September 10, 2026
11:43 AM
0

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account.
According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.
"Talos' analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors," Cisco Talos said.
The company is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988.
CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.
CVE-2026-20316 has a CVSS score of 5.3 and allows attackers to log in to FMC using static credentials for a low-privileged account. However, Cisco rates the flaw as High severity because it can be combined with other FMC vulnerabilities to elevate privileges.
Cisco has already released hot fixes for both vulnerabilities and is urging customers to install them immediately. The company is also releasing a more comprehensive hardening that includes patches for additional vulnerabilities next week.
Qilin ransomware deployed after FMC breach
Talos attributed one of the intrusion clusters, tracked as UAT-11988, with high confidence to Qilin ransomware affiliates.
The threat actor accessed an FMC device using static credentials associated with CVE-2026-20316, then abused legitimate built-in FMC tools to perform reconnaissance of the victim's network.
The attackers collected hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.
Talos says the collected information was staged in publicly accessible files on the compromised FMC server and downloaded using HTTP GET requests.
The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.
After reconnaissance, the threat actor used post-exploitation tools including Impacket, Invoke-TheHash, and custom EDR killers.
Ultimately, the attackers deployed Qilin ransomware on endpoints to encrypt files.
APT hackers deploy Cyclops Blink
A second intrusion cluster, tracked as UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tooling overlaps with the Sandworm APT group.
Sandworm is a Russian state-sponsored hacking group linked to the Russia's military intelligence agency, GRU, and is known for conducting destructive cyberattacks against governments and critical infrastructure.
The attackers gained access to FMC devices either by exploiting CVE-2026-20079 or using the static credentials associated with CVE-2026-20316.
After gaining access, the threat actors modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure. The malicious license file was then executed as root using Cisco's legitimate package_info.pl utility.
Talos says it believes UAT-11823 exploited both CVE-2026-20079 and CVE-2026-20316 during the attacks.
The attackers also deployed scripts that collected configuration data from managed devices and stored it in archives for later exfiltration.
UAT-11823 ultimately deployed a variant of Cyclops Blink on compromised devices, a modular Linux malware family previously attributed to the Russian Sandworm threat group.
The Cyclops Blink variant acts as a backdoor, providing persistent access, credential theft, and the ability to sniff network traffic.
Third cluster steals credentials
The third cluster, tracked as UAT-12197, exploited CVE-2026-20079 and deployed a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory.
The web shell was then used to install a malicious JAR file named cmd.jar, which allowed them to execute commands on the server.
The attackers used this JAR file to query internal databases on compromised systems and steal user authentication data and credentials.
Confirms link between July attacks
The Talos report also answered ongoing questions about the exploitation of the two vulnerabilities first disclosed in July.
As BleepingComputer reported on July 29, Cisco disclosed that CVE-2026-20316 was being actively exploited and warned that it could be chained with other FMC vulnerabilities to elevate privileges.
At the same time, Cisco updated its advisory for CVE-2026-20079 with the same /var/tmp/license.tmp indicator of compromise used for CVE-2026-20316, but did not confirm that the authentication bypass flaw was also being exploited.
BleepingComputer contacted Cisco at the time to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 was also being exploited, and why the same indicator appeared in both advisories.
Cisco did not answer those questions directly, instead just sharing a statement urging customers to install the hotfixes as soon as possible.
Talos has now confirmed that UAT-11823 exploited both vulnerabilities and used the malicious license.tmp mechanism during its attacks.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksCisco warns of FMC static credential flaw exploited in zero-day attacksNew 'BlueMoon' kit exploited Windows and Chrome zero-day flawsGoogle warns of new Chrome zero-day bug exploited in attacksMagento StyleSmuggler zero-day exploited to deploy Linux backdoor

Actively Exploited
Cisco
Cisco Secure FMC
CVE-2026-20079
CVE-2026-20316
Zero-Day

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Overdue a password health-check? Audit your Active Directory for free

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Cisco Talos reports that two recently patched vulnerabilities in the Secure Firewall Management Center (FMC) have been exploited by three distinct threat clusters linked to both ransomware gangs and state-sponsored hackers. These exploits targeted CVE-2026-20079, a maximum severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that permits login using low-privileged accounts. The analysis detailed by Cisco Talos identified three specific post-compromise activities associated with these attacks, tracked under the identifiers UAT-12197, UAT-11823, and UAT-11988.

The exploitation of these flaws led to a variety of malicious actions across the compromised FMC devices. For instance, the threat cluster UAT-11988 was attributed with high confidence to Qilin ransomware affiliates. These attackers first gained access using static credentials associated with CVE-2026-20316 to perform network reconnaissance, gathering sensitive information such as hostnames, IP addresses, directory listings, Active Directory service account credentials, and various domain account details. This collected data was staged in publicly accessible files and downloaded via HTTP GET requests. Following reconnaissance, the attackers established persistence and control by deploying a Python SOCKS5 proxy and a reverse SSH tunnel to maintain access, forwarding critical ports including LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM. Subsequently, they utilized post-exploitation tools like Impacket and Invoke-TheHash before ultimately deploying Qilin ransomware across the endpoints to encrypt files.

A second intrusion cluster, UAT-11823, was linked by Talos to an advanced persistent threat actor exhibiting toolsets overlapping with the Sandworm APT group, a Russian state-sponsored hacking entity known for targeting critical infrastructure. This group achieved access either through the exploitation of CVE-2026-20079 or the use of static credentials from CVE-2026-20316. After gaining entry, these actors modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure, executing it as root via Cisco's legitimate package_info.pl utility. Furthermore, this cluster deployed a variant of Cyclops Blink, a modular Linux malware family previously attributed to Sandworm, which functions as a backdoor enabling persistent access, credential theft, and network traffic sniffing. These actors also deployed scripts to collect configuration data from managed devices for later exfiltration.

The third cluster, UAT-12197, leveraged CVE-2026-20079 to deploy a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory. This web shell was then employed to install a malicious JAR file named cmd.jar, which granted the attackers command execution capabilities on the server. This malicious JAR file was used to query internal databases on compromised systems, successfully stealing user authentication data and credentials.

Talos also confirmed a direct link between the exploitation of the two vulnerabilities. While Cisco disclosed CVE-2026-20316 as being actively exploited and warning of privilege escalation potential, the same indicator of compromise, /var/tmp/license.tmp, was used in both advisories. Talos has confirmed that UAT-11823 exploited both known vulnerabilities simultaneously, utilizing the license.tmp mechanism during its attacks. The report underscores the fact that even with valid credentials, only a fraction of an attacker's potential actions are blocked, and prevention scores often fail to account for activities that occur after initial access is achieved.