Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco FMC Exploits Fuel Ransomware, Credential Theft

Rows of network equipment and servers in a dimly lit operations room.

"Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.

How the FMC flaws work (CVE-2026-20079 and CVE-2026-20316)

Cisco disclosed two recently patched flaws in its Secure Firewall Management Center (FMC) software that have been actively exploited by multiple groups. CVE-2026-20079, rated with a CVSS score of 10.0, is an authentication bypass in the FMC web interface that can allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

The second vulnerability, CVE-2026-20316 (CVSS score: 5.3), can permit an unauthenticated, remote attacker to log in to a vulnerable device using a low-privilege account and thereby access sensitive data within susceptible systems. Cisco warned that CVE-2026-20316 can be paired with other Secure FMC vulnerabilities to elevate privileges.

Three Talos-identified clusters: UAT-12197, UAT-11823, UAT-11988

Cisco Talos reported three distinct clusters of post-compromise activity tied to state-sponsored and crimeware actors exploiting the FMC flaws.

  • UAT-12197: Exploitation of CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor. Talos said the cluster used those tools to query internal databases and obtain user authentication data and credentials.
  • UAT-11823: Use of both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell, two bash scripts designed to harvest managed-device configurations, and a variant of Cyclops Blink — a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm, according to Talos.
  • UAT-11988: A ransomware operation that exploited CVE-2026-20316 for initial access and then relied on legitimate built-in FMC tooling as part of a living-off-the-land (LotL) campaign to map and prepare the environment for encryption.

UAT-11988 and Qilin ransomware: living-off-the-land tactics

Talos described UAT-11988 as a ransomware operation that combined initial access via CVE-2026-20316 with heavy use of FMC’s legitimate capabilities. After gaining access, the actors conducted extensive reconnaissance of the victim’s environment, dropped tunneling tools to maintain network access, collected credentials, and built a target list of endpoints to encrypt.

According to the report, the operators also terminated security tools and deployed Qilin ransomware on selected systems. The use of built-in management tooling and LotL techniques was a deliberate choice to blend malicious activity with normal administrative behavior, Talos said.

CISA KEV listings and the federal patch deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, triggering a requirement for Federal Civilian Executive Branch (FCEB) agencies to apply the patch by September 12, 2026. CISA had already added CVE-2026-20316 to the KEV catalog in late July 2026.

Cisco’s public guidance aligns with the federal actions: the vendor has released hotfixes for the affected software versions and announced plans to ship a comprehensive hardening release next week for multiple internally discovered vulnerabilities.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Apply the Cisco hotfixes for CVE-2026-20079 and CVE-2026-20316 without delay, tests and monitoring for signs of the specific post-compromise behaviors Talos described — JSP web shells, JAR executors, Netcat reverse shells, bash scripts that harvest device configurations, and the presence of tunneling tools or credential dumps.
  • Policymakers and regulators: The inclusion of CVE-2026-20079 and CVE-2026-20316 in CISA’s KEV catalog has set a federal compliance timeline; agencies must patch by the specified date, and the chronology underscores how exploited vulnerabilities can trigger mandatory remediation for FCEB entities.
  • Affected enterprises and procurement leaders: Expect Cisco to release a hardening update next week and plan to validate hotfix deployment across managed FMC instances. Enterprises should be aware that attackers used both direct exploitation and LotL tactics to collect credentials and stage ransomware — detection and response playbooks will need to account for false-normal activity generated by legitimate FMC tooling.

The public record in this advisory is compact but stark: two patched FMC flaws have been weaponized by at least three distinct threat clusters to steal credentials, move laterally, and — in one operation — deploy Qilin ransomware after methodical reconnaissance and use of built-in tooling. Cisco’s hotfixes, the forthcoming hardening release, and CISA’s KEV listings form the immediate defensive milestones; how quickly organizations apply them will determine whether these incidents remain isolated or widen into further compromise.

Original story