Skip to content
Tech News
← Back to articles

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

Security appliances that sit at the network edge are now prime targets, and Cisco's Secure Firewall Management Center is the latest example: a CVSS 10.0 authentication bypass and a static-credential flaw are already being exploited by three distinct threat clusters, including Qilin ransomware affiliates and state-linked actors. Because FMC manages firewall policy across an organization, a compromise gives attackers root-level control and a trusted foothold for lateral movement. Hot fixes exist, so the burden is on defenders to patch fast and hunt for signs of prior intrusion.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — When attackers get in through authentication bypasses and static credentials, hardware-backed logins are the kind of defense that doesn't hand over a password. The YubiKey 5 NFC plugs into USB-A or taps an NFC phone to add phishing-resistant two-factor authentication across admin accounts, VPNs, and password managers. It's a pocket-sized upgrade for anyone who just read about credential theft and wants fewer reusable secrets floating around.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.

The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account.

According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.

"Talos' analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors," Cisco Talos said.

The company is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988.

CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.

CVE-2026-20316 has a CVSS score of 5.3 and allows attackers to log in to FMC using static credentials for a low-privileged account. However, Cisco rates the flaw as High severity because it can be combined with other FMC vulnerabilities to elevate privileges.

Cisco has already released hot fixes for both vulnerabilities and is urging customers to install them immediately. The company is also releasing a more comprehensive hardening that includes patches for additional vulnerabilities next week.

Qilin ransomware deployed after FMC breach

Talos attributed one of the intrusion clusters, tracked as UAT-11988, with high confidence to Qilin ransomware affiliates.

... continue reading