8
Cisco Talos says three separate threat clusters linked to ransomware and state-sponsored attacks exploited two recently patched vulnerabilities in Cisco Secure Firewall Management Center (FMC) appliances.
The attacks targeted CVE-2026-20079, a critical authentication bypass vulnerability, and CVE-2026-20316, a static-credentials flaw that allowed attackers to log in using a low-privileged account.
After compromising FMC devices, the attackers deployed web shells, stole credentials, created reverse shells and network proxies, and gathered information about victims’ internal networks. One attack led to the deployment of Qilin ransomware, while another involved Cyclops Blink, malware previously attributed to the Russian Sandworm threat group.
“Talos analysis shows three clusters of post-compromise activity on FMC instances related to state-sponsored and crimeware threat actors,” Cisco Talos said.
Cisco is tracking the activity clusters as UAT-12197, UAT-11823, and UAT-11988.
CVE-2026-20079 has a maximum CVSS score of 10.0. The flaw allows an unauthenticated remote attacker to bypass authentication and execute commands as root on a vulnerable FMC device.
CVE-2026-20316 has a CVSS score of 5.3 and allows attackers to log in to FMC using static credentials associated with a low-privileged account. Cisco rates the vulnerability as High severity because it can potentially be combined with other FMC flaws to escalate privileges.
Cisco has released hotfixes for both vulnerabilities and is urging customers to install them immediately. The company also plans to release additional security enhancements and patches for further vulnerabilities.
Qilin ransomware deployed after Cisco FMC breach
Talos has high confidence that the intrusion cluster tracked as UAT-11988 is associated with a Qilin ransomware affiliate.
The attackers used the static credentials linked to CVE-2026-20316 to access an FMC device. They then abused legitimate built-in FMC tools to conduct reconnaissance across the victim’s network.
The stolen information included hostnames, IP addresses, directory listings, Active Directory service account credentials, MySQL credentials, domain account information, computer lists, and hostname-to-IP address mappings for internal servers and infrastructure.
According to Talos, the attackers staged the collected data in publicly accessible files on the compromised FMC server and downloaded it using HTTP GET requests.
The threat actors then deployed a Python SOCKS5 proxy and a reverse SSH tunnel to maintain access to internal systems. The tunnels forwarded traffic for LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM.
After conducting reconnaissance, the attackers used post-exploitation tools including Impacket, Invoke-TheHash, and a custom endpoint detection and response (EDR) killer.
The attackers ultimately deployed Qilin ransomware to endpoints, encrypting files across the victim’s environment.
Sandworm-linked attackers deploy Cyclops Blink
The second intrusion cluster, UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tools and techniques overlap with the Sandworm APT group.
Sandworm is a Russian state-sponsored hacking group associated with Russia’s military intelligence agency, the GRU. The group is known for targeting governments, critical infrastructure, and other high-value organizations.
The attackers gained access to Cisco FMC devices by exploiting CVE-2026-20079 or by using the static credentials associated with CVE-2026-20316.
After gaining access, the attackers used a malicious file named license.tmp to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure. The file was executed with root privileges through the legitimate Cisco package_info.pl utility.
Talos believes UAT-11823 exploited both CVE-2026-20079 and CVE-2026-20316 during the intrusion.
The attackers also deployed a script that collected configuration data from managed devices and stored it in an archive for later exfiltration.
UAT-11823 eventually deployed a variant of Cyclops Blink, a modular Linux malware family previously attributed to Sandworm.
Cyclops Blink variants provide persistent access, support credential theft, and can enable attackers to monitor network traffic.
Third threat cluster steals credentials
The third cluster, UAT-12197, exploited CVE-2026-20079 to deploy a JavaServer Pages (JSP)-based web shell in the Cisco Security Manager Tomcat webroot directory.
The attackers then installed a malicious JAR file named cmd.jar through the web shell. The file allowed them to execute commands on the compromised server.
The attackers used the JAR file to query internal databases and steal user authentication data and credentials.
Talos confirms connection between July Cisco FMC attacks
The Talos report also provides additional details about the exploitation of the two vulnerabilities first disclosed in July.
On July 29, Cisco revealed that CVE-2026-20316 was being actively exploited and warned that attackers could chain it with other FMC vulnerabilities to escalate privileges.
Cisco also updated the advisory for CVE-2026-20079 with similar information. The indicator of compromise /var/tmp/license.tmp had been associated with exploitation of CVE-2026-20316, but it was initially unclear whether the authentication bypass vulnerability was also being exploited.
BleepingComputer previously contacted Cisco to ask whether the two vulnerabilities were connected, whether CVE-2026-20079 was being exploited, and why similar metrics appeared in both advisories.
Cisco did not directly answer those questions at the time, instead urging customers to install the available hotfixes as soon as possible.
Talos has now confirmed that UAT-11823 exploited both vulnerabilities and used the malicious license.tmp mechanism during the attack.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about AI-speed attacks, modern defense strategies, and how organizations can verify, decide, fix, and revalidate threats at machine speed.
Source: www.bleepingcomputer.com



