Cisco Firewalls Under Siege: State-Sponsored and Ransomware Groups Exploit Critical Vulnerabilities
Cisco has issued a critical warning regarding active exploitation of two recently patched vulnerabilities in its **Secure Firewall Management Center (FMC)** software. Three distinct threat clusters, including state-sponsored actors and ransomware gangs, are leveraging these flaws to gain root access, steal credentials, and deploy ransomware.
Network security firm **Cisco** has disclosed that its **Secure Firewall Management Center (FMC)** software has been actively exploited by three distinct threat clusters. These sophisticated groups, ranging from state-sponsored entities to ransomware operators, have leveraged two recently patched vulnerabilities to compromise systems.
### Critical Authentication Bypass Under Attack
At the heart of these attacks is **CVE-2026-20079**, an authentication bypass vulnerability with a critical **CVSS score of 10.0**. This flaw, residing in the web interface of **FMC** software, allows an unauthenticated, remote attacker to bypass authentication and execute script files. This grants them root access to the underlying operating system.
The second vulnerability, **CVE-2026-20316** (CVSS score: 5.3), permits an unauthenticated, remote attacker to log in to an affected device using a low-privilege account. While less severe on its own, it can be combined with other **Cisco Secure FMC** vulnerabilities to escalate privileges and access sensitive data.
### Threat Clusters and Their Tactics
**Cisco Talos** identified three specific clusters of post-compromise activity associated with these exploits:
* **UAT-12197**: This group exploited **CVE-2026-20079** to deploy JSP-based web shells and a Java Archive (JAR)-based command executor. Their objective was to query internal databases and exfiltrate user authentication data and credentials.
* **UAT-11823**: This cluster leveraged both **CVE-2026-20079** and **CVE-2026-20316**. They deployed a **Netcat**-based reverse shell, two bash scripts to harvest managed-device configurations, and a variant of **Cyclops Blink**. **Cyclops Blink** is a modular ELF implant previously attributed to the Russian state-sponsored hacking group **Sandworm**.
* **UAT-11988**: Identified as a ransomware operation, this group exploited **CVE-2026-20316** for initial access. They then utilized legitimate built-in **FMC** tooling as part of a living-off-the-land (LotL) attack. Their activities included extensive reconnaissance, deploying tunneling tools for persistence, credential harvesting, terminating security tools, and ultimately deploying **Qilin** ransomware on selected systems.
### Urgent Call for Patching
**Cisco** strongly advises all customers to apply the hotfixes already released for **CVE-2026-20079** and **CVE-2026-20316**. The company also announced plans to release a comprehensive hardening update for various internally discovered vulnerabilities in the coming week.
Both vulnerabilities have been added to the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**'s **Known Exploited Vulnerabilities (KEV)** catalog. **CVE-2026-20079** was added recently, with Federal Civilian Executive Branch (**FCEB**) agencies required to apply patches by September 12, 2026. **CVE-2026-20316** was added to the **KEV** catalog in late July 2026, underscoring the severity and widespread exploitation of these flaws.
