Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Patch now! Cisco warns of state & criminal hackers targeting a pair of Secure Firewall Management Center vulnerabilities

The Russian Sandworm group and the Qilin ransomware gang are among several threat actors exploiting bugs in Cisco’s FMC software.

Fri, 11 Sep 2026
Patch now! Cisco warns of state & criminal hackers targeting a pair of Secure Firewall Management Center vulnerabilities

Cisco’s threat intelligence arm, Talos, has warned the company’s customers of active and widespread exploitation of a pair of vulnerabilities in its Secure Firewall Management Center software.

The first vulnerability, CVE-2026-20079, is a Critical authentication bypass vulnerability first disclosed in March 2026, while the second, CVE-2026-20316, rates a CVSS score of only 5.3 and was disclosed in July. However, despite that low score, Talos said the vulnerability can be used in tandem with other FMC vulnerabilities to elevate privileges.

“Due to Talos identifying in-the-wild abuse of these CVEs, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316,” Talos said in a September 9 blog post.

 
 

“A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 14th).”

So far, Talos is tracking three clusters of malicious activity, with both criminal and state-sponsored actors getting in on the action.

The first cluster, tracked as UAT-12197, does not appear to be linked to any known threat actor, and largely involves credential theft via a Java Archive-based command executor to deploy a web shell. This activity is exploiting CVE-2026-20079.

The second cluster, tracked under the moniker UAT-11823, is most likely a known advanced persistent threat actor, most likely the Russian Sandworm group, based on the tooling being used. In this case, the APT is compromising systems either via static credentials or CVE-2026-20079.

“After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server,” Talos said.

“This mechanism of deploying malicious package files is likely an indicator of the exploitation of CVE-2026-20316, a vulnerability that allows a remote attacker to log in using a low-privileged account.”

The actor then deployed malware – a variant of Cyclops Blink – capable of establishing persistence, tracking downloads, harvesting credentials, and packet sniffing. Cyclops Blink is a modular tool known to be used by Sandworm in past campaigns.

The third and final cluster, which Talos is tracking as UAT-11988, is thought to be ransomware-related, most likely the Qilin ransomware-as-a-service operation.

Talos has observed this activity exploiting CVE-2026-20316 to log onto an FMC device with static credentials before the threat actor performs network reconnaissance, credential theft, and establishes a list of endpoints for encryption.

“The threat actor also staged a SOCKS proxy and reverse-SSH tunnel to forward ports from internal hosts back to their own infrastructure,” Talos said.

“Once all these preliminary actions were completed, the operator began conducting additional probes within the compromised network, deploying antivirus (AV) killers and ultimately the Qilin ransomware family.”

Indicators of compromise for these threat clusters can be found in the Talos blog and on its GitHub repository.

Earlier this year, the Australian Signals Directorate’s Australian Cyber Security Centre, along with its Five Eyes and other European partners, warned of ongoing cyber activity targeting vulnerable network devices, with Russian state-sponsored hackers the culprit.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: