Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Cisco FMC Vulnerability Exposited: A Threat Assessment of the Recently Patched Secure Firewall Management Center Vulnerabilities


Recently patched Cisco FMC vulnerabilities have been exploited by threat actors to deploy Qilin ransomware on targeted systems. A total of three threat clusters have been identified, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warning Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.

  • Cisco FMC has confirmed that three distinct threat clusters are exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
  • The vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have been identified as being used in conjunction with ransomware and state-sponsored attacks.
  • CVE-2026-20079 is an authentication bypass vulnerability with a CVSS score of 10.0, allowing remote attackers to obtain root access to the underlying operating system.
  • CVE-2026-20316 is a log-in vulnerability with a CVSS score of 5.3, allowing remote attackers to access sensitive data within susceptible systems.
  • Cisco Talos has identified three clusters of post-compromise activity associated with state-sponsored and crimeware threat actors.
  • The clusters, named UAT-12197, UAT-11823, and UAT-11988, have been observed to exploit the vulnerabilities to carry out malicious activities.
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.



  • In a recent revelation, Cisco FMC has confirmed that three distinct threat clusters have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. These vulnerabilities, specifically CVE-2026-20079 and CVE-2026-20316, have been identified as being used in conjunction with ransomware and state-sponsored attacks. The exploitation of these vulnerabilities has led to the deployment of Qilin ransomware on targeted systems.

    CVE-2026-20079, which has a CVSS score of 10.0, is an authentication bypass vulnerability in the web interface of FMC software. This vulnerability allows an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device, thereby obtaining root access to the underlying operating system. The second vulnerability, CVE-2026-20316, has a CVSS score of 5.3 and allows an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems.

    Cisco Talos, a cybersecurity research firm, has identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These clusters, which have been named UAT-12197, UAT-11823, and UAT-11988, have been observed to be exploiting the aforementioned vulnerabilities to carry out a range of malicious activities. UAT-12197, for example, has been observed to deploy JSP-based web shells and a Java Archive (JAR)-based command executor to query internal databases and obtain user authentication data and credentials.

    UAT-11823, on the other hand, has been observed to exploit both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell, two bash scripts to harvest managed-device configurations, and a variant of Cyclops Blink, a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm. UAT-11988, a ransomware operation, has been observed to exploit CVE-2026-20316 for initial access and then use legitimate built-in FMC tooling as part of a living-off-the-land (LotL) attack to conduct extensive reconnaissance of the victim's environment, drop tunneling tools to maintain network access, collect credentials, build a target list of endpoints to encrypt, terminate security tools, and deploy Qilin ransomware on selected systems.

    In light of this new information, Cisco has issued a warning to its customers, advising them to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316. The company has also announced plans to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also taken notice of the vulnerability, adding CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, was added to the KEV catalog in late July 2026.

    In conclusion, the exploitation of the recently patched Secure Firewall Management Center (FMC) vulnerabilities has resulted in the deployment of Qilin ransomware on targeted systems. It is imperative that customers take immediate action to patch these vulnerabilities and protect themselves against the malicious activities carried out by these threat clusters.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Cisco-FMC-Vulnerability-Exposited-A-Threat-Assessment-of-the-Recently-Patched-Secure-Firewall-Management-Center-Vulnerabilities-ehn.shtml

  • https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-20079

  • https://www.cvedetails.com/cve/CVE-2026-20079/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-20316

  • https://www.cvedetails.com/cve/CVE-2026-20316/


  • Published: Fri Sep 11 03:38:15 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us