Attackers Exploit Cisco FMC Bugs to Lock Targets with Qilin Ransomware

Cisco has confirmed that two recently patched flaws in its Secure Firewall Management Center (FMC) are being actively exploited by multiple threat groups, including nation-state actors and ransomware gangs. The vulnerabilities, now added to federal exploit catalogs, are facilitating credential theft and widespread deployment of Qilin ransomware. The disclosure comes as Cisco warns customers to patch immediately.

Critical Vulnerabilities Under Fire

The first flaw—CVE-2026-20079—carries the maximum CVSS score of 10.0. An authentication bypass in FMC’s web interface allows remote, unauthenticated attackers to execute scripts that grant root access to the device’s underlying operating system. A second vulnerability, CVE-2026-20316 (CVSS score 5.3), lets an unauthenticated attacker log in with low-privilege credentials and access sensitive data. It can be chained with other FMC bugs to elevate privileges further.

Multiple Threat Clusters, Multiple Objectives

Cisco Talos has tracked three distinct post-compromise campaigns—dubbed UAT-12197, UAT-11823, and UAT-11988—each leveraging one or both of these flaws.

  • UAT-12197 uses CVE-2026-20079 to deploy JSP-based web shells and a JAR-based command executor. These tools are used to query internal databases and harvest user credentials.
  • UAT-11823 exploits both CVE-2026-20079 and CVE-2026-20316 to launch Netcat reverse shells, execute bash scripts to exfiltrate FMC-managed device configurations, and even drop a variant of Cyclops Blink—an ELF implant tied to the Russian Sandworm group.
  • UAT-11988 involves ransomware. It begins with exploitation of CVE-2026-20316, then uses legitimate FMC tools to conduct reconnaissance, maintain access via tunneling, collect credentials, choose endpoints for encryption, kill security tools, and finally launch Qilin ransomware.

Urgent Fixes & Compliance Pressures

Cisco has already released hotfixes for both CVE-2026-20079 and CVE-2026-20316, and promises a more extensive hardening patch set for related vulnerabilities to ship next week. In parallel, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal civilian agencies apply the patch by September 12, 2026. The second flaw, CVE-2026-20316, was added to the KEV list in late July 2026.

FMC is Cisco’s management platform used to configure, monitor, and maintain many of its firewall and unified threat defense products. It acts as the control layer across device fleets in enterprise networks—making flaws in it especially dangerous. Attackers who gain FMC access can issue commands that affect entire networks.

This campaign reflects growing sophistication in how attackers chain pre-authentication flaws with living-off-the-land techniques and legitimate tools. The use of web shells, implants, tunneling, and ransomware in one operation indicates a move towards more integrated intrusion strategies—especially in patches that aren’t applied in time.

Analysts should watch whether sprawl from FMCs across organizations will lead to supply-chain style fallout, particularly in sectors bound by stringent compliance rules. Patching is one thing; detecting misuse after breach is another. The danger here isn’t just what’s exposed—it’s how far an attacker can move once they’re inside.