Cisco Firewalls Hacked by State-Sponsored Actors Using Critical Flaws
Cisco's Secure Firewall Management Center and its cloud-delivered version have been exploited by state-sponsored and ransomware threat actors, according to the networking equipment maker's threat intelligence team.
The flaws were discovered in two bugs: a high-severity authentication bypass vulnerability (CVE-2026-20079) and a hard-coded password flaw (CVE-2026-20316).
Cisco Talos observed three clusters of post-compromise activity that exploited one or both of the flaws. The first cluster, UAT-12197, used the authentication bypass vulnerability to deploy web shells and a Java Archive-based command executor.
The second cluster was attributed to advanced threat actor UAT-11823, which overlaps in tooling with the Russian intelligence agency actor known as Sandworm (Unit 74455 of Russia's General Staff Main Intelligence Directorate). This group exploited both firewall management flaws to plant Cyclops Blink malware.
The third cluster is likely a Qilin ransomware operator capitalizing on the static credential vulnerability. The threat actor logged into a centralized management console, performed reconnaissance, and stole sensitive data, including host names, IP addresses, and credentials for Active Directory service accounts and MySQL accounts.