Cisco FMC vulnerabilities used in Qilin ransomware attacks

Cisco has disclosed active exploitation of two Secure Firewall Management Center (FMC) vulnerabilities by three separate threat clusters associated with ransomware and state-sponsored activity. The flaws are CVE-2026-20079, an authentication bypass rated CVSS 10.0, and CVE-2026-20316, a CVSS 5.3 issue that permits unauthenticated remote login through a low-privilege account.
CVE-2026-20079 affects the FMC web interface and can allow an unauthenticated remote attacker to bypass authentication, execute script files and obtain root access to the underlying operating system. CVE-2026-20316 can expose sensitive data through low-privilege access and may be combined with other Secure FMC vulnerabilities to elevate privileges.
Three clusters showed distinct post-compromise activity
Cisco Talos identified UAT-12197 exploiting CVE-2026-20079 to install JSP web shells and a Java Archive-based command executor. The tooling was used to query internal databases and obtain user authentication data and credentials.
UAT-11823 exploited both vulnerabilities, deploying a Netcat-based reverse shell and two bash scripts designed to harvest managed-device configurations. The cluster also delivered a Cyclops Blink variant, a modular ELF implant previously attributed to the Russian state-sponsored Sandworm group.
UAT-11988 used CVE-2026-20316 for initial access. It then relied on legitimate built-in FMC tools in a living-off-the-land operation to perform broad reconnaissance, retain network access with tunnelling tools, collect credentials and compile a list of endpoints for encryption.
Ransomware deployment followed reconnaissance
After building its target list, UAT-11988 terminated security tools and deployed Qilin ransomware on selected systems. The activity illustrates how an administrative management platform can become a valuable foothold when its exposed software is not patched. The wider pattern of Cisco-related exposure is reflected in Cisco vulnerability chains and attack activity examining Cisco vulnerability chains and related attack activity.
Cisco urged customers to apply released hotfixes for both CVE-2026-20079 and CVE-2026-20316. The company also said it intends to issue a comprehensive hardening release for internally discovered vulnerabilities the following week.
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog and set a 12 September 2026 remediation deadline for Federal Civilian Executive Branch agencies. CVE-2026-20316 entered the catalog in late July 2026.
Operational priority for FMC administrators
Organizations operating affected FMC versions should install Cisco's hotfixes, examine FMC instances for JSP web shells, reverse shells and unexpected scripts, and investigate unusual configuration harvesting, credential collection, tunnelling activity or endpoint targeting. Treating FMC as a high-value management asset and responding to signs of compromise can help limit the path from initial access to ransomware deployment.

