Cisco FMC Flaws Exploited by Three Threat Groups for Ransomware and State-Sponsored Activity
Cisco has warned customers of three separate threat groups exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls and gain root access.
The second flaw, CVE-2026-20316, can be chained with other FMC vulnerabilities to increase privileges. Cisco linked the attacks to ransomware operations, including Qilin, as well as state-sponsored activity.
Cisco Talos identified three attack clusters targeting Cisco Secure Firewall Management Center (FMC). The first cluster involves the exploitation of CVE-2026-20079 and the subsequent deployment of web shells and custom command executors into Tomcat webroot directories. This allows attackers to query internal databases and harvest user authentication data and credentials.
The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells and installs the modular ELF malware 'Cyclops Blink' for persistent access and packet sniffing. The third cluster involves Qilin ransomware operators (UAT-11988) who use static credentials for initial access and deploy SOCKS proxies and reverse-SSH tunnels.
Cisco strongly urges customers to immediately apply released hotfixes and update detection rules using the provided Snort SIDs while awaiting upcoming comprehensive security hardening updates. CISA added CVE-2026-20079 to its KEV catalog, requiring U.S. federal agencies to patch it by September 12, 2026.