Skip to content
Cybersecurity

Cisco Firewall Flaws Exploited to Deploy Qilin Ransomware

Cisco Secure Firewall Management Center vulnerabilities exploited in ransomware attacks

Cisco has confirmed that threat actors are exploiting two recently patched vulnerabilities in its Secure Firewall Management Center (FMC) software, with attacks ranging from credential theft to ransomware deployment. Cisco Talos has identified three separate intrusion clusters using one or both flaws against vulnerable FMC systems.

The vulnerabilities are tracked as CVE-2026-20079 and CVE-2026-20316. The first is a critical authentication-bypass flaw with a maximum CVSS score of 10.0 that can allow an unauthenticated remote attacker to execute commands with root privileges. The second involves static credentials for a low-privileged account and can provide attackers with access that may be combined with other vulnerabilities to gain higher privileges.

Qilin Attackers Deploy Ransomware

One of the intrusion clusters, tracked by Cisco Talos as UAT-11988, has been attributed with high confidence to Qilin ransomware affiliates. The attackers used the static credentials associated with CVE-2026-20316 to access an FMC device before carrying out reconnaissance across the victim's network.

The attackers collected information including hostnames, IP addresses, Active Directory service-account credentials, MySQL credentials and details about internal systems. They then established additional access using a SOCKS5 proxy and reverse SSH tunnel before deploying post-exploitation tools and eventually Qilin ransomware on endpoints.

Sandworm-Linked Activity Detected

A second cluster, UAT-11823, has been linked with high confidence to activity associated with Sandworm, the Russian state-sponsored group connected to Russia's military intelligence service. The attackers gained access through one or both of the Cisco vulnerabilities and modified a file called license.tmp to establish a reverse shell.

The campaign then used Cisco's legitimate package_info.pl utility to execute the malicious file with root privileges. The attackers collected configuration information from managed firewalls and deployed a variant of Cyclops Blink, a Linux malware family previously associated with Sandworm. The malware can provide persistent access and support credential theft, command execution and network traffic monitoring.

Third Attack Focused on Credentials

Talos identified a third cluster, UAT-12197, exploiting CVE-2026-20079. Attackers installed a JSP-based web shell in the Cisco Security Manager Tomcat webroot and used it to deploy a malicious JAR file capable of executing commands.

The attackers then used the malicious software to query internal databases and collect authentication information and credentials. The activity shows that compromising the firewall-management layer can give attackers visibility and access beyond the affected management server itself.

Cisco Urges Immediate Patching

Cisco has already released hotfixes for both vulnerabilities and is urging customers to install them as soon as possible. The company has also said a broader security-hardening release covering these fixes and additional vulnerabilities is planned for the week of September 16.

Cisco previously confirmed that CVE-2026-20316 was being exploited in the wild. It has now also confirmed active exploitation of CVE-2026-20079. The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog and set September 12 as the remediation deadline for affected federal civilian agencies.

The latest findings make the risk more immediate for organisations using vulnerable FMC deployments. Installing the available fixes can prevent further exploitation, but organisations that find indicators of compromise should also investigate the affected systems because patching alone does not remove an attacker who may already have gained access.