ZeroHour

Search: “UAT-12197”

4 stories

Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware

State-sponsored and ransomware actors actively exploit critical Cisco FMC flaws CVE-2026-20079 (CVSS 10.0) and CVE-2026-20316 to gain root access and deploy ransomware.

Cisco Talos confirmed in-the-wild exploitation of CVE-2026-20079 (CVSS 10.0, unauthenticated authentication bypass enabling root command execution) and CVE-2026-20316 (CVSS 5.3, hard-coded static credentials) in Cisco Secure Firewall Management Center. Three activity clusters were identified: UAT-12197 dropping a JSP web shell and credential harvester; UAT-11823, assessed as Sandworm, deploying a Cyclops Blink variant; and UAT-11988, a Qilin ransomware affiliate chaining the flaws before deploying ransomware. CISA added both CVEs to the KEV catalog with a September 12 remediation deadline for federal agencies.

Cyber Security News · 7d agoExploit / PoC in the wildCVE-2026-20079CVE-2026-20316

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos reports in-the-wild exploitation of critical FMC flaw CVE-2026-20079 by three clusters including a Sandworm-linked APT and Qilin ransomware affiliates.

Cisco Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center that lets unauthenticated remote attackers execute scripts and obtain root access, and CVE-2026-20316 (CVSS 5.3), which permits low-privileged logins and can be chained for privilege escalation. Talos identified three post-compromise clusters: UAT-12197 deploying JSP web shells and a JAR command executor for credential theft; UAT-11823, an APT overlapping with Sandworm, deploying a Netcat reverse shell and Cyclops Blink malware; and UAT-11988, assessed as a ransomware operator with TTPs consistent with Qilin affiliates. Hotfixes are available, with a comprehensive hardening release due the week of September 14, 2026.

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.

Cisco Talos identified three post-compromise clusters exploiting recently patched Cisco Secure Firewall Management Center flaws. UAT-12197 deploys JSP web shells and harvests credentials; UAT-11823 (with Sandworm-overlapping tooling) installs Cyclops Blink for persistence; UAT-11988 (Qilin) uses static credentials, extensive reconnaissance, SOCKS5 proxies, reverse-SSH tunnels, AV killers, and ransomware deployment. CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 patch deadline for federal agencies; Cisco urges immediate hotfix application.

Security Affairsupdated · 1h agofirst · 6d agoExploit / PoC in the wild 8 sourcesCVE-2026-20079CVE-2026-203165· 2 reads

Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA warn that critical FMC authentication bypass CVE-2026-20079 is actively exploited; CISA added it to the KEV catalog with a September 12 deadline.

Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center allowing remote, unauthenticated attackers to run malicious scripts and gain root access via crafted HTTP requests. Cisco patched the flaw in early March and added IoCs in late July, but confirmed active exploitation in its September 9 advisory; CISA added it to the KEV catalog requiring federal remediation by September 12. Talos identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored and financially motivated actors, and this is the third FMC vulnerability in KEV this year after CVE-2026-20316 and CVE-2026-20131.