Critical Cisco FMC Flaw Exploited in Qilin Ransomware Attacks

Critical Cisco FMC Flaw Exploited in Qilin Ransomware Attacks

Two patched Cisco FMC vulnerabilities, including a critical authentication bypass, are being exploited to steal credentials and deploy Qilin ransomware.

Cisco FMC vulnerabilities are being actively exploited by three separate threat clusters to steal credentials, harvest managed-device configurations, and deploy Qilin ransomware, according to new details published by Cisco Talos. The attacks target two recently patched flaws in Cisco Secure Firewall Management Center (FMC), a centralized platform that lets network teams manage firewall policies and devices across an organization.

The more severe issue, CVE-2026-20079, carries a CVSS score of 10.0, the highest possible severity rating. It is an authentication bypass vulnerability in the web interface of FMC software. An unauthenticated, remote attacker can exploit it to bypass the normal login process and execute script files on an affected device, ultimately gaining root access to the underlying operating system. Root access means full administrative control over the FMC server, allowing an attacker to read or change anything on that system.

The second flaw, CVE-2026-20316, has a CVSS score of 5.3. It allows an unauthenticated, remote attacker to log in to an affected device using a low-privilege account and then access sensitive data within susceptible systems. Cisco notes that this weakness can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges, meaning an attacker who initially gets only limited access can combine this bug with another flaw to gain much higher control.

Cisco Talos identified three distinct clusters of post-compromise activity on FMC instances, linked to both state-sponsored and crimeware threat actors. The first, tracked as UAT-12197, exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor. These tools let the attackers query internal databases and obtain user authentication data and credentials, effectively harvesting the login information needed to move further into a victim network.

The second cluster, UAT-11823, exploited both CVE-2026-20079 and CVE-2026-20316. It delivered a Netcat-based reverse shell, two bash scripts designed to harvest managed-device configurations, and a variant of Cyclops Blink. Cyclops Blink is a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm. This cluster focused on collecting configuration details from devices managed by the FMC, which could reveal network topology, access rules, and other sensitive security settings.

The third cluster, UAT-11988, is a ransomware operation. It used CVE-2026-20316 for initial access and then relied on legitimate built-in FMC tooling in a living-off-the-land (LotL) attack. LotL means the attackers used tools already present on the system instead of installing obvious malware, making their activity harder to detect. With this approach, UAT-11988 conducted extensive reconnaissance of the victim's environment, dropped tunneling tools to maintain network access, collected credentials, built a target list of endpoints to encrypt, terminated security tools, and deployed Qilin ransomware on selected systems.

Cisco strongly advises customers to apply hotfixes for affected software versions already released for CVE-2026-20079 and CVE-2026-20316. The company also said it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week. In addition, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply the patches by September 12, 2026. CVE-2026-20316 was added to the KEV catalog in late July 2026.

For organizations running Cisco FMC or similar centralized network management platforms, the immediate priorities are to install the available hotfixes, limit access to the management interface, and review administrative accounts for signs of unauthorized use. For website owners and businesses that rely on managed hosting, keeping all management consoles and plugins up to date is equally important, because attackers routinely target unpatched web interfaces and admin panels. AEU-I offers security-first IT, infrastructure and consulting to help teams manage patching, harden exposed management interfaces, and respond to potential intrusions.

How to Protect Yourself

  1. If your company uses Cisco Secure Firewall Management Center, ask your IT team to install Cisco's hotfix for CVE-2026-20079 and CVE-2026-20316 right away.
  2. Keep the FMC management interface off the public internet, or restrict it to trusted internal networks only.
  3. Turn on an extra login step, such as a code from a phone app, for any administrator account that can reach the firewall management console.
  4. After patching, have your IT team check FMC logs for unexpected administrator logins or new user accounts.
  5. Change any firewall administrator passwords that may have been exposed, and do not reuse those passwords anywhere else.

Vulnerabilities & Fixes

Terms Explained

  • CVE Common Vulnerabilities and Exposures, a public list that gives each known software security flaw a unique ID number.
  • CVSS score A number from 0 to 10 used to rate how severe a software vulnerability is, with 10 being the most critical.
  • authentication bypass A weakness that lets someone skip the normal login step and get into a system without a valid password.
  • web shell A small hidden program placed on a server that lets an attacker send commands through a web browser.
  • root access Full administrative control over a computer, allowing the user to read, change, or delete anything.
  • reverse shell A connection that lets an attacker remotely control a computer by making the target computer reach out to the attacker.
  • ransomware Malicious software that locks or encrypts files and demands payment to unlock them.
  • living-off-the-land A tactic where attackers use tools already built into a system instead of installing obvious malware, making them harder to detect.

Related AEU services

  • AEU-I IT and security consulting