Cisco has revealed that multiple threat groups linked to ransomware operations and state-sponsored activity have been exploiting two recently patched vulnerabilities in Secure Firewall Management Center (FMC) software. The attacks involved attempts to gain unauthorized access, steal credentials, conduct reconnaissance, and deploy malware on affected environments. Cisco Talos identified three separate clusters of post-compromise activity targeting FMC instances, highlighting how attackers are using vulnerable security management systems as entry points into enterprise networks.
The first exploited vulnerability, CVE-2026-20079, is a critical authentication bypass issue in the web interface of Cisco Secure FMC with a CVSS score of 10.0. The flaw could allow an unauthenticated remote attacker to bypass authentication controls and execute script files on an affected device, eventually gaining root access to the underlying operating system. The second vulnerability, CVE-2026-20316, carries a CVSS score of 5.3 and allows an unauthenticated remote attacker to access affected systems through a low-privilege account and obtain sensitive information. Cisco noted that this vulnerability can also be combined with other Secure FMC weaknesses to increase access privileges. According to Cisco Talos, one activity cluster tracked as UAT-12197 exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive-based command executor. These tools were used to interact with internal databases and obtain user authentication information and credentials from compromised systems.
Another cluster, identified as UAT-11823, exploited both CVE-2026-20079 and CVE-2026-20316 to deliver additional tools, including a Netcat-based reverse shell and bash scripts designed to collect managed-device configurations. Cisco Talos also observed a variant of Cyclops Blink, a modular ELF implant previously associated with the Sandworm group, being deployed during this activity. The third cluster, UAT-11988, was linked to ransomware activity and used CVE-2026-20316 for initial access. After gaining entry, attackers relied on legitimate Cisco FMC tools as part of a living-off-the-land approach to explore victim environments, maintain network access through tunneling tools, collect credentials, identify systems for encryption, disable security solutions, and eventually deploy Qilin ransomware on selected devices. The activity demonstrates how attackers are combining vulnerability exploitation with legitimate system features to remain less visible while expanding their access.
Cisco has advised customers to apply available hotfixes for affected software versions addressing CVE-2026-20079 and CVE-2026-20316. The company also stated that it plans to release a broader hardening update covering additional internally identified vulnerabilities. The security updates come as CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply patches by September 12, 2026. CVE-2026-20316 was added to the same catalog earlier in July 2026 due to active exploitation activity. Organizations using Cisco Secure Firewall Management Center are advised to prioritize updates, review system activity for unusual access patterns, and monitor for signs of credential theft, unauthorized configuration changes, and ransomware-related behavior.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





