"Talos' analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors," Cisco Talos said.
CVE-2026-20079 and CVE-2026-20316: how the flaws were used
Cisco Talos mapped three distinct intrusion clusters that exploited two recently patched Secure Firewall Management Center (FMC) vulnerabilities: CVE-2026-20079, an authentication bypass with a maximum CVSS score of 10.0, and CVE-2026-20316, a static-credential issue rated 5.3. Talos reported attackers used these entry points to gain initial access to FMC devices, then to run scripts as root or authenticate with a low-privileged account that could be chained to escalate privileges.
UAT-11988: static credentials, reconnaissance, and Qilin ransomware
Talos attributed UAT-11988 with high confidence to affiliates of Qilin ransomware. According to the report, attackers accessed an FMC device using the static credentials tied to CVE-2026-20316 and then abused legitimate FMC tooling for reconnaissance. Collected data included hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP mappings. Talos says that information was staged in publicly accessible files on the compromised FMC server and retrieved via HTTP GET requests.
To maintain access the actors deployed a Python SOCKS5 proxy and a reverse SSH tunnel, forwarding LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM ports. Post-exploitation tools documented by Talos included Impacket, Invoke-TheHash, and custom EDR killers. The chain ended with deployment of Qilin ransomware on endpoints to encrypt files.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageUAT-11823: license.tmp, Netcat reverse shell, and Cyclops Blink
Talos assigned UAT-11823 to an advanced persistent threat actor whose tooling overlaps with Sandworm, which the report describes as "a Russian state-sponsored hacking group linked to the Russia's military intelligence agency, GRU." The cluster exploited FMC devices via CVE-2026-20079 and/or CVE-2026-20316. Attackers modified a license.tmp file to establish a Netcat-based reverse shell to their command-and-control infrastructure, then executed the malicious license as root using Cisco's package_info.pl utility.
The actors collected managed-device configuration data, archived it for exfiltration, and ultimately deployed a variant of Cyclops Blink — a modular Linux malware family previously attributed to Sandworm. Talos notes this Cyclops Blink variant functions as a backdoor providing persistent access, credential theft, and network-traffic sniffing.
UAT-12197: JSP web shell and credential theft
The third cluster, UAT-12197, exploited CVE-2026-20079 and placed a JSP-based web shell into the Cisco Security Manager Tomcat webroot. The web shell installed a malicious JAR named cmd.jar that allowed command execution on the server. Talos says attackers used cmd.jar to query internal databases and steal user authentication data and credentials.
Cisco response, prior disclosures, and the immediate operational lift
Cisco released hot fixes for both vulnerabilities and is urging customers to install them immediately; the company also said it will release a more comprehensive hardening that includes patches for additional vulnerabilities next week. Talos’ findings confirm that the same /var/tmp/license.tmp indicator that appeared in Cisco advisories in late July was used in attacks that exploited both CVE-2026-20079 and CVE-2026-20316. BleepingComputer reported on July 29 that Cisco disclosed active exploitation of CVE-2026-20316; at that time Cisco did not directly confirm whether CVE-2026-20079 was also being exploited.
Talos is tracking the three clusters as UAT-12197, UAT-11823, and UAT-11988 and has linked the clusters to both crimeware affiliates (Qilin) and state-aligned APT tooling (Cyclops Blink/Sandworm overlap).
What this means for Cisco customers, incident responders, and policymakers
- Cisco customers and security teams: Talos’ narrative underscores the need to install the released hot fixes and follow the upcoming hardening updates. The report documents how attackers leveraged FMC-native tools and legitimate utilities (package_info.pl, built-in reconnaissance functions) to move from foothold to full network access.
- Incident responders and forensic teams: Indicators cited by Talos — the license.tmp mechanism, JSP web shell in the Tomcat webroot, cmd.jar, and artifacts tied to SOCKS5/reverse SSH tunnels — should be prioritized for triage and hunt activity in environments using FMC.
- Policymakers and regulators: Talos’ linkage of state-sponsored tooling and crimeware affiliates to the same vulnerable management appliance highlights cross-cutting risk where a single vulnerable management plane can enable both espionage-focused persistence and ransomware-driven disruption.
Talos’ report ties a clear thread from initial FMC compromise to three distinct operational outcomes: credential theft, persistent backdoors, and large-scale ransomware encryption. Cisco’s hot fixes and the promised hardening are the immediate defensive steps, but the report itself illustrates a simple technical fact: once FMC is compromised, attackers used legitimate tools and straightforward tunnels to reach internal systems. As Talos notes and the Blue Report 2026 echoes, "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The practical takeaway is a narrow, urgent one for affected organizations: apply the fixes, hunt for the documented indicators, and assume that any unexplained FMC access may already have been used to map and touch internal infrastructure.
Source: BleepingComputer — Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers




