Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account.
According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.
"Talos' analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors," Cisco Talos said.
The company is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988.
CVE-2026-20079 has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts as root on vulnerable FMC devices.
CVE-2026-20316 has a CVSS score of 5.3 and allows attackers to log in to FMC using static credentials for a low-privileged account. However, Cisco rates the flaw as High severity because it can be combined with other FMC vulnerabilities to elevate privileges.
Cisco has already released hot fixes for both vulnerabilities and is urging customers to install them immediately. The company is also releasing a more comprehensive hardening that includes patches for additional vulnerabilities next week.
Qilin ransomware deployed after FMC breach
Talos attributed one of the intrusion clusters, tracked as UAT-11988, with high confidence to Qilin ransomware affiliates.
... continue reading