Skip to content
Back to Guavy Wire
Stocks

Cisco FMC Flaws Exploited by Three Threat Groups for Ransomware and State-Sponsored Activity

Instruments
CSCO
Share

Cisco has warned customers of three separate threat groups exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls and gain root access.

The second flaw, CVE-2026-20316, can be chained with other FMC vulnerabilities to increase privileges. Cisco linked the attacks to ransomware operations, including Qilin, as well as state-sponsored activity.

Cisco Talos identified three attack clusters targeting Cisco Secure Firewall Management Center (FMC). The first cluster involves the exploitation of CVE-2026-20079 and the subsequent deployment of web shells and custom command executors into Tomcat webroot directories. This allows attackers to query internal databases and harvest user authentication data and credentials.

The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells and installs the modular ELF malware 'Cyclops Blink' for persistent access and packet sniffing. The third cluster involves Qilin ransomware operators (UAT-11988) who use static credentials for initial access and deploy SOCKS proxies and reverse-SSH tunnels.

Cisco strongly urges customers to immediately apply released hotfixes and update detection rules using the provided Snort SIDs while awaiting upcoming comprehensive security hardening updates. CISA added CVE-2026-20079 to its KEV catalog, requiring U.S. federal agencies to patch it by September 12, 2026.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc