Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.
Cisco Talos identified three post-compromise clusters exploiting recently patched Cisco Secure Firewall Management Center flaws. UAT-12197 deploys JSP web shells and harvests credentials; UAT-11823 (with Sandworm-overlapping tooling) installs Cyclops Blink for persistence; UAT-11988 (Qilin) uses static credentials, extensive reconnaissance, SOCKS5 proxies, reverse-SSH tunnels, AV killers, and ransomware deployment. CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 patch deadline for federal agencies; Cisco urges immediate hotfix application.
- CVE-2026-20079 is a critical unauthenticated authentication bypass enabling remote script execution and potential root access.
- CVE-2026-20316 allows sensitive data access via low-privilege accounts and can be chained for privilege escalation.
- Three clusters tracked: UAT-12197 web shells, UAT-11823 Cyclops Blink, and UAT-11988 Qilin ransomware operations.
- Qilin operators used impacket, Invoke-TheHash, and custom AV killers before encrypting selected endpoints.
- CISA KEV deadline of September 12, 2026 requires US federal agencies to patch CVE-2026-20079.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) |
Full article533 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 11, 2026

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware.
Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run scripts and potentially gain root access. Attackers also exploit CVE-2026-20316 to access sensitive data through a low-privilege account. The second flaw can be chained with other FMC vulnerabilities to increase privileges.
Cisco linked the attacks to ransomware operations, including Qilin, as well as state-sponsored activity.
“Talos’ analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors, as described below.” reads the advisory. “The first cluster which we track as UAT-12197, involves the exploitation of CVE-2026-20079, leading to the deployment of web shells, a Java Archive (JAR)-based command executor, and credential exfiltration.”
Talos identified three attack clusters targeting Cisco Secure Firewall Management Center (FMC). The first cluster deploys JSP-based web shells and custom command executors into Tomcat webroot directories to query internal databases and harvest user authentication data and credentials.
“This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory.” reads the report. “The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:”
The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells, harvests device configurations, and installs the modular ELF malware “Cyclops Blink” for persistent access, DNS over HTTPS resolution, and packet sniffing.
“The threat actor obtained initial access to compromised systems by either exploiting CVE-2026-20079 or via static credentials.” Talos states. “After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:”
The third cluster involves Qilin ransomware operators (UAT-11988) who use static credentials for initial access, perform extensive domain reconnaissance, deploy SOCKS proxies and reverse-SSH tunnels, and execute AV killers before deploying ransomware.
“Once extensive reconnaissance was completed, the threat actor attempted to establish persistent network access into the victim organization using a Python SOCKS5 proxy (socks5.py) and a reverse-SSH tunnel from the FMC back to the attacker’s own remote host. The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report. “The threat actor conducted extensive probing of endpoints in the victim’s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers — all followed by the deployment of the Qilin ransomware on selected endpoints.”
Cisco strongly urges customers to immediately apply released hotfixes and update detection rules using the provided Snort SIDs while awaiting upcoming comprehensive security hardening updates.
CISA added CVE-2026-20079 to its KEV catalog, requiring U.S. federal agencies to patch it by September 12, 2026. CVE-2026-20316 was added in late July.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Cisco FMC)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/198884/cyber-crime/attackers-exploit-critical-cisco-fmc-flaw-to-deploy-qilin-ransomware.html