Severity
High
Analysis Summary
Researcher has confirmed the active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, posing a significant risk because FMC serves as the centralized management platform for enterprise firewalls. The most critical flaw, CVE-2026-20079 (high), allows unauthenticated remote attackers to bypass authentication and execute scripts with root privileges by hijacking an unclaimed system process created during device startup. Cisco patched the vulnerability in March 2026 but confirmed in September that exploitation began in August, prompting CISA to add it to the Known Exploited Vulnerabilities (KEV) catalog.
The second vulnerability, CVE-2026-20316 (medium), is caused by hard-coded static credentials associated with a low-privileged account, allowing remote attackers to gain unauthorized access. Although the flaw provides limited privileges by itself, attackers can combine it with CVE-2026-20079 or other vulnerabilities to achieve privilege escalation. Cisco released fixes for this vulnerability in July 2026, and it was also added to CISA's KEV catalog. The active exploitation demonstrates that attackers are targeting FMC not only for initial access but also as a pathway into broader enterprise environments.
Researcher identified three distinct attack clusters following successful compromise. UAT-12197 exploited the authentication bypass to deploy a JSP web shell into the FMC Tomcat webroot and then installed cmd.jar, a Java-based command executor capable of querying internal databases and stealing stored credentials. UAT-11823, assessed with high confidence as overlapping with the Russian military-linked Sandworm group, chained both vulnerabilities, replaced a legitimate license file with a malicious Makeself package, established a Netcat reverse shell, exfiltrated configurations, and deployed a Cyclops Blink variant. The malware supports persistence, DNS-over-HTTPS command-and-control, credential theft, packet sniffing, and remote command execution.
The third cluster, UAT-11988, is assessed with high confidence as a Qilin ransomware operator that exploited the static-credential vulnerability without using the authentication bypass. After gaining access, the attackers harvested Active Directory and MySQL credentials, identified domain controllers, file servers, and Exchange infrastructure, and moved laterally using LDAP, Kerberos, SMB, NetBIOS, and WinRM through SOCKS5 and reverse-SSH tunnels. They subsequently deployed security-disabling tools and Qilin ransomware on selected endpoints. Organizations using Secure FMC should immediately apply the available fixes for CVE-2026-20079 and CVE-2026-20316 and avoid waiting for the broader hardening release. If immediate patching is not possible, FMC management interfaces should be restricted from internet exposure to reduce the attack surface.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2026-20079
CVE-2026-20316
IP
- 89.34.96.56
- 208.123.119.215
- 104.218.165.253
- 91.214.78.118
- 43.204.2.142
Remediation
- Block all threat indicators at your respective controls.
- Search for indicators of compromise (IOCs) in your environment utilizing your respective security controls
- Immediately apply the latest Cisco security updates addressing CVE-2026-20079 and CVE-2026-20316 on all affected Secure FMC systems.
- Restrict FMC management interfaces from direct internet exposure and allow access only from trusted administrative networks.
- Monitor FMC systems for unauthorized accounts, web shells, modified files, suspicious scripts, and unexpected administrative activity.
- Investigate for indicators associated with Cyclops Blink, Qilin ransomware, Netcat reverse shells, and unauthorized Java/JSP files.
- Review FMC logs and authentication records for unexpected remote logins, authentication bypass attempts, and use of suspicious or static credentials.
- Rotate FMC, Active Directory, MySQL, and other credentials that may have been exposed following a compromise.

