Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Critical Flaws in Cisco FMC Exposed Users to Ransomware and State-Sponsored Attacks

A recent report from Cisco Talos has revealed that two previously patched vulnerabilities in the Secure Firewall Management Center (FMC) have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. The flaws, which were patched in June 2026, allowed attackers to bypass authentication and execute scripts as root on vulnerable FMC devices, or log in using static credentials for a low-privileged account.

The first cluster, tracked as UAT-11988, was attributed with high confidence to Qilin ransomware affiliates. These attackers accessed an FMC device using static credentials associated with CVE-2026-20316 and then used legitimate built-in FMC tools to perform reconnaissance of the victim’s network. They collected sensitive information such as hostnames, IP addresses, directory listings, and Active Directory service account credentials, which was staged in publicly accessible files on the compromised FMC server.

The Qilin ransomware gang used this information to deploy a Python SOCKS5 proxy and reverse SSH tunnel to maintain access to internal systems and forwarded ports for various services. They then deployed post-exploitation tools including Impacket, Invoke-TheHash, and custom EDR killers before ultimately deploying Qilin ransomware on endpoints to encrypt files.

A second cluster, tracked as UAT-11823, was attributed by Talos with high confidence to an advanced persistent threat actor whose tooling overlaps with the Sandworm APT group. This state-sponsored hacking group is linked to Russia’s military intelligence agency and has been known for conducting destructive cyberattacks against governments and critical infrastructure.

The attackers in this cluster gained access to FMC devices either by exploiting CVE-2026-20079 or using the static credentials associated with CVE-2026-20316. They modified a license file to establish a Netcat-based reverse shell connecting to their command-and-control infrastructure, before deploying scripts that collected configuration data from managed devices and stored it in archives for later exfiltration.

The third cluster, tracked as UAT-12197, exploited CVE-2026-20079 and deployed a JSP-based web shell into the Cisco Security Manager Tomcat webroot directory. This web shell was then used to install a malicious JAR file, which allowed the attackers to steal credentials and maintain access to internal systems.

The exploitation of these critical flaws highlights the importance of prompt patching and regular security updates for FMC devices. With both vulnerabilities now patched, customers are urged to install hot fixes immediately to prevent potential attacks. Cisco will also be releasing a more comprehensive hardening guide next week that includes patches for additional vulnerabilities.

For users still running vulnerable FMC versions, it is essential to take immediate action to protect against these threats. This includes applying the latest security updates and monitoring network activity closely for signs of suspicious behavior.


Source: Bleeping Computer — 2026-09-10