Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Cisco FMC flaws exploited by ransomware and state-sponsored clusters

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three threat clusters linked to ransomware and state-sponsored attacks.

The attacks used CVE-2026-20079, a maximum-severity authentication bypass with a CVSS score of 10.0, and CVE-2026-20316, a static-credential flaw with a CVSS score of 5.3. Cisco rates the second flaw High because it can be combined with other FMC vulnerabilities to elevate privileges. Cisco has released hot fixes for both flaws and is preparing broader hardening with additional patches next week.

Talos tracks the clusters as UAT-12197, UAT-11823, and UAT-11988. It attributed UAT-11988 with high confidence to Qilin ransomware affiliates, who used compromised FMC devices to gather network information, maintain access through proxies and tunnels, and deploy Qilin ransomware.

UAT-11823 was attributed with high confidence to a state-sponsored actor whose tooling overlaps with Sandworm. The cluster exploited both vulnerabilities, used a modified license.tmp file and Cisco's package_info.pl utility to establish a root reverse shell, and deployed a Cyclops Blink variant. UAT-12197 used CVE-2026-20079 to install a JSP web shell and a malicious JAR named cmd.jar.

The Blue Report 2026 measures defenses across 338 million simulations in customer production environments.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.