INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco FMC Vulnerabilities Exploited for Credential Theft and Ransomware

| 2026-09-11 06:19 CRITICAL HIGH
Executive Summary AI-generated
The threat cluster linked to Cisco's FMC vulnerabilities has been identified as a distinct attack vector, leveraging two recently patched Secure Firewall Management Center (FMC) vulnerabilities. This cluster is comprised of three separate incidents: UAT-12197 and UAT-11823, which exploited CVE-2026-20079 for authentication bypass and Netcat-based reverse shell delivery; UAT-11988, a ransomware operation that used legitimate FMC tooling as part of a living-off-the-land attack. The attacks also involved the exploitation of CVE-2026-20316, allowing an unauthenticated remote attacker to log in using a low-privilege account and access sensitive data within susceptible systems. As a result, Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting these vulnerabilities since September 11, 2026.
Technical Mitigations AI-generated
* Apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316 to prevent exploitation of the identified vulnerabilities. * Implement a secure patch management strategy to ensure timely deployment of security patches, including regular updates and monitoring for potential exploits. * Conduct thorough risk assessments and vulnerability scans on network devices and systems to identify potential entry points for attackers exploiting known vulnerabilities like CVE-2026-20079 and CVE-2026-20316. * Use intrusion detection and prevention systems (IDPS) with robust signature-based or behavioral analysis capabilities to detect and block suspicious activity related to the identified vulnerabilities. * Implement a secure configuration management process to ensure that Cisco Secure FMC software is properly configured, patched, and maintained on all affected devices.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilinCyclops BlinkCyclops Blink CVE-2026-20316CVE-2026-20316 CVE-2026-20079CVE-2026-20079
Target & Sectors
Global Scope
Incident Timeline
‎late July 2026
The CVE-2026-20316 vulnerability was added to the KEV catalog in late July 2026, allowing threat actors to exploit it on Cisco FMC systems.
vulnerability CVE-2026-20316
organisation KEV
‎Sep 11, 2026
Threat actors used the Cisco FMC web interface authentication bypass vulnerability (CVE-2026-20079) to log in and access sensitive data on affected devices.
infrastructure 10.0
organisation FMC
organisation Cisco
organisation Cisco Secure FMC
‎2026/09/11
UAT-11823 exploited CVE-2026-20316 to gain initial access, then used the JAR-based command executor (cmd[.]jar) to query internal databases for user authentication data and credentials.
organisation Sandworm
organisation Russian APT
organisation Cisco FMC Flaws Exploited
organisation FMC
financial 3 Cluster
organisation AV
organisation Invoke-TheHash
organisation LOTL
organisation IP
organisation Hostname
organisation ADFS
organisation Cisco’s Secure FMC
organisation CVSS
financial 1 Cluster
organisation Attacker
organisation Cisco Secure FMC
organisation Modular
organisation DNS
organisation HTTPS (DoH
organisation Secure Firewall Management Center
organisation users;\
organisation Makeself
organisation UAT-12197 cmd[.]jar
organisation Cisco Secure Firewall Management Center
organisation JSP
organisation JAR
organisation APT
financial 2 Cluster
organisation Sandworm APT
organisation ELF
organisation SSH
organisation license[.]tmp
organisation SMB
organisation NETBIOS
data_breach 445 SMB
data_breach 135 NETBIOS
organisation TAC
organisation Attacker IP
‎September 12, 2026
Threat actors exploited CVE-2026-20079 in Cisco FMC to steal credentials and deployed Qilin Ransomware.
vulnerability CVE-2026-20079
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎Week of September 14th
Threat actors exploited known vulnerabilities in Cisco FMC to gain unauthorized access and steal credentials.
‎Week of September 16th
Threat actors exploited known vulnerabilities in Cisco FMC to gain unauthorized access and deploy Qilin Ransomware.
Tactical Metrics
Metrics
infrastructure
‎10.0
Software Version
Metrics
financial
3
Cluster
Metrics
financial
1
Cluster
Metrics
financial
2
Cluster
Metrics
data_breach
445
Smb
Metrics
data_breach
135
Netbios
Intelligence Sources