Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Three distinct threat clusters (state-sponsored and crimeware) are actively exploiting two Cisco Secure FMC vulnerabilities: CVE-2026-20079 (CVSS 10.0, authentication bypass) and CVE-2026-20316 (CVSS 5.3, low-privilege account access) UAT-12197 deploys JSP-based web shells and JAR command executors to harvest credentials from internal databases UAT-11823 combines both CVEs to deliver reverse shells, harvest device configurations, and deploy a Sandworm-linked Cyclops Blink ELF implant UAT-11988 i
Analysis
TL;DR
- Three distinct threat clusters (state-sponsored and crimeware) are actively exploiting two Cisco Secure FMC vulnerabilities: CVE-2026-20079 (CVSS 10.0, authentication bypass) and CVE-2026-20316 (CVSS 5.3, low-privilege account access)
- UAT-12197 deploys JSP-based web shells and JAR command executors to harvest credentials from internal databases
- UAT-11823 combines both CVEs to deliver reverse shells, harvest device configurations, and deploy a Sandworm-linked Cyclops Blink ELF implant
- UAT-11988 is a ransomware operation using CVE-2026-20316 for initial access, living-off-the-land techniques, and Qilin ransomware deployment
- CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, with a patch deadline of September 12, 2026 for federal agencies
Why It Matters
This is a critical real-world exploitation scenario involving high-severity vulnerabilities in widely deployed network infrastructure, demonstrating how unpatched management interfaces can serve as gateways for both nation-state espionage and ransomware campaigns. The involvement of Sandworm-linked tooling and active Qilin ransomware deployment underscores the urgency for organizations running Cisco Secure FMC to prioritize patching immediately.
Technical Details
- CVE-2026-20079 (CVSS 10.0): Authentication bypass in the FMC web interface allowing unauthenticated remote attackers to execute script files and obtain root access to the underlying OS
- CVE-2026-20316 (CVSS 5.3): Allows unauthenticated login via low-privilege accounts to access sensitive data; can be chained with other FMC vulnerabilities for privilege escalation
- UAT-12197: Exploits CVE-2026-20079 to deploy JSP-based web shells and JAR-based command executors targeting internal database credential extraction
- UAT-11823: Chains both CVEs to deliver Netcat reverse shells, bash scripts for configuration harvesting, and a Cyclops Blink variant (modular ELF implant attributed to Sandworm)
- UAT-11988: Uses CVE-2026-20316 for initial access, then employs living-off-the-land tactics including built-in FMC tooling for reconnaissance, tunneling tools for persistence, credential theft, endpoint enumeration, security tool termination, and Qilin ransomware deployment
Industry Insight
- Organizations using Cisco Secure FMC should treat patching as an emergency; the combination of active exploitation, nation-state involvement, and ransomware deployment makes this a top-priority remediation item
- The use of living-off-the-land techniques by UAT-11988 highlights the importance of monitoring legitimate administrative tooling for anomalous behavior, not just malicious binaries
- The CISA KEV catalog inclusion with a September 12, 2026 deadline signals that federal supply chain and critical infrastructure operators must be patched well in advance of that date to remain compliant
Disclaimer: The above content is generated by AI and is for reference only.