Cyber Security News

Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware

Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with state-sponsored hacking groups and a ransomware affiliate leveraging the flaws to seize root access, plant malware, and stage attacks on enterprise networks.

The disclosure marks one of the year’s more serious enterprise security incidents, given FMC’s role as the central console administrators use to manage fleets of Cisco firewalls.

Hackers Exploit Cisco Firewall Flaw

The more dangerous of the two bugs, tracked as CVE-2026-20079, carries a perfect CVSS score of 10.0 and allows an unauthenticated remote attacker to bypass login controls entirely.

The flaw stems from an improper system process created when an FMC device boots up; if the resulting session is never claimed by a legitimate user, an attacker can hijack it and use it to execute scripts with root privileges over the underlying operating system.

Cisco patched the issue in March 2026, but confirmed on September 9 that its Product Security Incident Response Team became aware of in-the-wild abuse beginning in August.

The U.S. Cybersecurity and Infrastructure Security Agency has since added the vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to remediate.

The second flaw, CVE-2026-20316, rates a comparatively modest 5.3 on the CVSS scale but stems from hard-coded, static credentials tied to a low-privileged account that let remote attackers log in without proper authorization.

On its own, the bug offers limited access, but Talos warns it becomes far more dangerous when chained with the authentication bypass or other FMC vulnerabilities to escalate privileges. Cisco disclosed and patched this issue in late July 2026, and CISA added it to the KEV catalog around the same time.

Talos researchers identified three separate clusters of post-compromise activity, each reflecting a different threat actor’s objectives, as detailed in Cisco Talos’s technical disclosure.

The first, designated UAT-12197, exploited the authentication bypass to plant a JSP-based web shell inside the FMC’s Tomcat webroot directory, then used it to drop a Java Archive command executor named “cmd.jar” capable of querying the device’s internal database to steal stored user credentials.

The second cluster, UAT-11823, is assessed with high confidence to be an advanced persistent threat actor overlapping with the Russian military-linked group Sandworm.

This group chained both CVEs, replaced a legitimate license file with a malicious Makeself package to establish a Netcat-based reverse shell, exfiltrated device configurations, and ultimately deployed a variant of the Cyclops Blink malware, a modular implant previously tied to Sandworm’s botnet operations against network edge devices.

The Cyclops Blink variant found on compromised FMC systems supports persistence via init.d scripts, DNS-over-HTTPS command-and-control resolution, credential harvesting, packet sniffing, and arbitrary remote command execution.

The third cluster, UAT-11988, is assessed with high confidence to be a Qilin ransomware operator that skipped the authentication bypass entirely, instead logging in through the static-credential flaw before living off the land using FMC’s own built-in administrative tooling.

The group harvested Active Directory and MySQL credentials, mapped domain controllers, file servers, and Exchange infrastructure, then tunneled deeper into victim networks over LDAP, Kerberos, SMB, NetBIOS, and WinRM using a Python SOCKS5 proxy and reverse-SSH connections before deploying antivirus killers and the Qilin ransomware payload on selected endpoints.

Threat ClusterAttribution & CapabilityExploitation MechanismPost-Compromise Tradecraft & Payload
UAT-12197Unattributed threat actorCVE-2026-20079 (Auth Bypass)Drops JSP web shell and cmd.jar to query internal DB and harvest credentials
UAT-11823Sandworm (Russian GRU nexus)Chained CVE-2026-20079 & CVE-2026-20316Trojanizes license files, executes Netcat shell, and deploys Cyclops Blink
UAT-11988Qilin ransomware affiliateCVE-2026-20316 (Static Credentials)Maps AD/Exchange, builds SOCKS5/SSH tunnels, and executes ransomware

Cisco and Talos are urging every organization running Secure FMC to apply the already-released hotfixes for both CVE-2026-20079 and CVE-2026-20316 immediately rather than waiting for a broader hardening release scheduled for the week of September 14, which will bundle these fixes with additional internally discovered patches.

Administrators who cannot patch immediately should also restrict FMC management interfaces from internet exposure, since this significantly reduces the attack surface for all three observed campaigns.

IOCClusterDescription
b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77dUAT-12197home.jsp — web shell
db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8eUAT-12197cmd.jar — JAR-based command executor
89.34.96[.]56UAT-11823Netcat-based reverse shell C2; also linked to Cyclops Blink C2 infrastructure
208.123.119[.]215UAT-11823Netcat-based reverse shell C2
104.218.165[.]253UAT-11823Attacker’s vulnerability scanner used to probe for CVE-2026-20079
91.214.78[.]118UAT-11823Netcat-based reverse shell C2
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461UAT-11823Cyclops Blink malware sample
43.204.2[.]142UAT-11988Attacker IP address used to conduct intrusions and stage the Qilin ransomware attack chain

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago