Cisco Secure FMC Flaws Exploited by Ransomware and State-Sponsored Hackers
What happened
Cisco Talos has published research confirming that two previously patched vulnerabilities in Secure Firewall Management Center (FMC) — the centralized console used to manage Cisco firewall deployments — have been actively exploited by at least three distinct threat clusters since the flaws were first disclosed in July. Talos is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988. Each followed a different post-compromise path: one deployed web shells and a custom command-execution tool to harvest authentication data from internal databases; a second, whose tradecraft overlaps with the Russian state-sponsored group known as Sandworm, planted a reverse shell and ultimately deployed a variant of the Cyclops Blink modular backdoor; and the third — attributed with high confidence to Qilin ransomware affiliates — used the compromised FMC device as a beachhead for extensive living-off-the-land reconnaissance before deploying Qilin ransomware across the victim's environment. Cisco has released hotfixes for both vulnerabilities and says a broader hardening release addressing additional internally discovered issues is coming shortly.
Who is affected
Any organization running Cisco Secure Firewall Management Center that has not applied the July hotfixes for CVE-2026-20079 and CVE-2026-20316 is at risk, particularly where the FMC web management interface is reachable from untrusted networks. Because FMC is a centralized management plane for firewall fleets, a single compromised instance can expose visibility and control over every managed device behind it, and the credentials, network diagrams, and configuration data harvested during reconnaissance can materially assist a subsequent ransomware operation.
Why it matters
This case is a clear illustration of how a single pair of vulnerabilities in security management infrastructure can be repurposed by very different classes of adversaries — an opportunistic ransomware crew, a nation-state espionage group, and a credential-harvesting operation — each pursuing distinct objectives through the same entry point. The Qilin cluster's use of legitimate, built-in FMC tooling for reconnaissance is notable because it blends into normal administrative activity and is harder to distinguish from routine operations using signature-based detection alone. The confirmed use of Cyclops Blink, previously attributed to Sandworm, also indicates that firewall management infrastructure is being targeted by actors with destructive and espionage intent, not just financially motivated groups.
Technical details
- CVE-2026-20079 — CVSS 10.0. Authentication bypass in the FMC web interface that allows an unauthenticated, remote attacker to execute script files as root on the underlying operating system.
- CVE-2026-20316 — CVSS 5.3 (rated High by Cisco due to chaining potential). Static/default credential issue allowing login to a low-privileged account, which can be combined with other FMC vulnerabilities to escalate privileges.
- UAT-12197: Exploited CVE-2026-20079 to deploy JSP-based web shells and a JAR-based command executor used to query internal databases and steal credentials.
- UAT-11823 (Sandworm-overlapping tooling): Exploited both CVEs, used a modified
license.tmpfile executed via a legitimate Cisco utility to establish a Netcat-based reverse shell, harvested managed-device configuration data, and deployed a Cyclops Blink variant for persistent backdoor access. - UAT-11988 (Qilin ransomware): Used CVE-2026-20316 for initial access, then relied on legitimate FMC tooling for reconnaissance, deployed tunneling tools, harvested Active Directory and MySQL credentials, disabled security tooling, and deployed Qilin ransomware.
- Cisco has released hotfixes for both vulnerabilities and plans an additional hardening release covering further internally discovered issues.
Recommended actions
- Apply Cisco's hotfixes for CVE-2026-20079 and CVE-2026-20316 immediately if this has not already been done; treat any unpatched, internet-reachable FMC instance as a priority incident.
- Restrict access to the FMC web management interface to trusted management networks only; it should never be directly reachable from the internet.
- Hunt for indicators of compromise, including unexpected modifications to
license.tmp, unfamiliar JSP web shells or JAR files in the Tomcat webroot, and unexplained outbound Netcat or reverse-shell connections from FMC hosts. - Review FMC and managed-device logs for signs of reconnaissance activity — unusual queries against internal databases, unexpected export of configuration data, or use of built-in tooling outside normal administrative patterns.
- If compromise is suspected, rotate all credentials accessible from or stored on the FMC instance, including Active Directory service accounts and any credentials used by managed devices.
- Monitor for the deployment of tunneling tools, EDR-killer utilities, or ransomware precursors on endpoints connected to the managed firewall environment, and ensure backups are isolated from the management network.
Sources
- https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html
- https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
