Cisco FMC Flaws Exploited by State-Sponsored Attackers and Ransomware Operators
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
The attacks leverage CVE-2026-20079, an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
The second flaw under exploitation is CVE-2026-20316, which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.
Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These include UAT-12197, which has exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor; UAT-11823, which has exploited both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell and Cyclops Blink; and UAT-11988, a ransomware operation that has exploited CVE-2026-20316 for initial access.