Cisco Talos has disclosed that three distinct threat clusters, tied to both ransomware operations and state-sponsored espionage, exploited two recently patched vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) software to breach networks, steal credentials, and in some cases deploy ransomware and destructive malware.
The attacks abused CVE-2026-20079, a maximum-severity (CVSS 10.0) authentication bypass flaw in the FMC web interface that lets an unauthenticated remote attacker execute scripts as root, and CVE-2026-20316, a CVSS 5.3 static credential vulnerability that allows login with a low-privileged account. Cisco rates the second flaw High severity because it can be chained with other FMC bugs to escalate privileges.
Three Clusters, Three Objectives
Talos is tracking the activity as three separate clusters: UAT-12197, UAT-11823, and UAT-11988.
- UAT-11988 was attributed with high confidence to Qilin ransomware affiliates. The group used the static credentials from CVE-2026-20316 to access FMC, then abused built-in FMC tools to harvest hostnames, IPs, Active Directory and MySQL credentials, and network mappings. Stolen data was staged in publicly accessible files on the compromised FMC server and pulled via HTTP GET requests. The attackers deployed a Python SOCKS5 proxy and reverse SSH tunnel, forwarded LDAP, Kerberos, SMB, and WinRM traffic, and used Impacket, Invoke-TheHash, and custom EDR killers before ultimately encrypting endpoints with Qilin ransomware.
- UAT-11823 shows tooling overlaps with the Sandworm APT group, linked to Russia’s GRU military intelligence and known for destructive attacks on critical infrastructure. This cluster exploited both CVE-2026-20079 and CVE-2026-20316, modified a license.tmp file to establish a Netcat reverse shell executed as root via Cisco’s legitimate package_info.pl utility, exfiltrated device configuration data, and deployed a variant of Cyclops Blink, a modular Linux backdoor previously tied to Sandworm that enables persistence, credential theft, and traffic sniffing.
- UAT-12197 exploited CVE-2026-20079 alone, planting a JSP web shell in the Cisco Security Manager Tomcat webroot and installing a malicious JAR file (cmd.jar) for further access and credential theft.
Patch Immediately
Cisco has released hot fixes for both vulnerabilities and is urging customers to apply them without delay. A more comprehensive hardening update addressing additional FMC vulnerabilities is expected next week. Given active exploitation by both ransomware crews and a suspected nation-state actor, organizations running FMC should treat patching as an emergency priority and hunt for indicators of the web shells, reverse shells, and proxy tooling described in Talos’ report.
