Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Recorded: Sept. 10, 2026, 4 p.m.
| Original | Summarized |
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers News Featured AdaptHealth confirms 4.1 million people exposed in July cyberattack Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Over 36,000 exposed Plex servers vulnerable to recent flaws New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers IDScan confirms breach tied to 153 million stolen driver’s licenses New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws The Top 4 Threats We Found by Investigating Every Alert for a Quarter Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityCisco FMC flaws exploited by ransomware gang, state-sponsored hackers Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers By Lawrence Abrams September 10, 2026 Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Actively Exploited Lawrence Abrams Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Sponsor Posts Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Overdue a password health-check? Audit your Active Directory for free See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Cisco Talos reports that two recently patched vulnerabilities in the Secure Firewall Management Center (FMC) have been exploited by three distinct threat clusters linked to both ransomware gangs and state-sponsored hackers. These exploits targeted CVE-2026-20079, a maximum severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that permits login using low-privileged accounts. The analysis detailed by Cisco Talos identified three specific post-compromise activities associated with these attacks, tracked under the identifiers UAT-12197, UAT-11823, and UAT-11988. The exploitation of these flaws led to a variety of malicious actions across the compromised FMC devices. For instance, the threat cluster UAT-11988 was attributed with high confidence to Qilin ransomware affiliates. These attackers first gained access using static credentials associated with CVE-2026-20316 to perform network reconnaissance, gathering sensitive information such as hostnames, IP addresses, directory listings, Active Directory service account credentials, and various domain account details. This collected data was staged in publicly accessible files and downloaded via HTTP GET requests. Following reconnaissance, the attackers established persistence and control by deploying a Python SOCKS5 proxy and a reverse SSH tunnel to maintain access, forwarding critical ports including LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM. Subsequently, they utilized post-exploitation tools like Impacket and Invoke-TheHash before ultimately deploying Qilin ransomware across the endpoints to encrypt files. A second intrusion cluster, UAT-11823, was linked by Talos to an advanced persistent threat actor exhibiting toolsets overlapping with the Sandworm APT group, a Russian state-sponsored hacking entity known for targeting critical infrastructure. This group achieved access either through the exploitation of CVE-2026-20079 or the use of static credentials from CVE-2026-20316. After gaining entry, these actors modified a license.tmp file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure, executing it as root via Cisco's legitimate package_info.pl utility. Furthermore, this cluster deployed a variant of Cyclops Blink, a modular Linux malware family previously attributed to Sandworm, which functions as a backdoor enabling persistent access, credential theft, and network traffic sniffing. These actors also deployed scripts to collect configuration data from managed devices for later exfiltration. The third cluster, UAT-12197, leveraged CVE-2026-20079 to deploy a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory. This web shell was then employed to install a malicious JAR file named cmd.jar, which granted the attackers command execution capabilities on the server. This malicious JAR file was used to query internal databases on compromised systems, successfully stealing user authentication data and credentials. Talos also confirmed a direct link between the exploitation of the two vulnerabilities. While Cisco disclosed CVE-2026-20316 as being actively exploited and warning of privilege escalation potential, the same indicator of compromise, /var/tmp/license.tmp, was used in both advisories. Talos has confirmed that UAT-11823 exploited both known vulnerabilities simultaneously, utilizing the license.tmp mechanism during its attacks. The report underscores the fact that even with valid credentials, only a fraction of an attacker's potential actions are blocked, and prevention scores often fail to account for activities that occur after initial access is achieved. |