threat_intelligence501 wordsRead on Arc Codex

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run scripts and potentially gain root access. Attackers also exploit CVE-2026-20316 to access sensitive data through a low-privilege account. The second flaw can be chained with other FMC vulnerabilities to increase privileges. Cisco linked the attacks to ransomware operations, including Qilin, as well as state-sponsored activity. “Talos’ analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors, as described below.” reads the advisory. “The first cluster which we track as UAT-12197, involves the exploitation of CVE-2026-20079, leading to the deployment of web shells, a Java Archive (JAR)-based command executor, and credential exfiltration.” Talos identified three attack clusters targeting Cisco Secure Firewall Management Center (FMC). The first cluster deploys JSP-based web shells and custom command executors into Tomcat webroot directories to query internal databases and harvest user authentication data and credentials. “This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory.” reads the report. “The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:” The second cluster, attributed to the advanced persistent threat actor UAT-11823 with tooling overlapping Sandworm, establishes Netcat reverse shells, harvests device configurations, and installs the modular ELF malware “Cyclops Blink” for persistent access, DNS over HTTPS resolution, and packet sniffing. “The threat actor obtained initial access to compromised systems by either exploiting CVE-2026-20079 or via static credentials.” Talos states. “After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:” The third cluster involves Qilin ransomware operators (UAT-11988) who use static credentials for initial access, perform extensive domain reconnaissance, deploy SOCKS proxies and reverse-SSH tunnels, and execute AV killers before deploying ransomware. “Once extensive reconnaissance was completed, the threat actor attempted to establish persistent network access into the victim organization using a Python SOCKS5 proxy (socks5.py) and a reverse-SSH tunnel from the FMC back to the attacker’s own remote host. The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).” concludes the report. “The threat actor conducted extensive probing of endpoints in the victim’s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers — all followed by the deployment of the Qilin ransomware on selected endpoints.” Cisco strongly urges customers to immediately apply released hotfixes and update detection rules using the provided Snort SIDs while awaiting upcoming comprehensive security hardening updates. CISA added CVE-2026-20079 to its KEV catalog, requiring U.S. federal agencies to patch it by September 12, 2026. CVE-2026-20316 was added in late July. Follow me on Twitter: @securityaffairs and Facebook and Mastodon (SecurityAffairs – hacking, Cisco FMC)

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.