Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks

Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware.

Sep 15, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cisco’s firewall management infrastructure has become an active entry point for ransomware operators and advanced threat actors. Cisco Talos said Sept. 9 that it is tracking three intrusion clusters exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC).

The campaigns include an advanced persistent threat actor whose tooling overlaps with Russia-linked Sandworm and a ransomware operator that ultimately deployed Qilin ransomware. Compromising FMC can expose credentials, firewall configurations, and pathways to systems deeper inside a network.

Talos documented attackers stealing credentials and firewall configurations, tunneling into internal networks, and probing downstream systems. Cisco firewall vulnerabilities affecting a centralized management platform can expose more than the FMC server itself.

Cisco FMC flaws open paths to internal systems

CVE-2026-20079 is a critical authentication-bypass vulnerability with a CVSS score of 10.0. An unauthenticated remote attacker can execute scripts and obtain root access. Cisco disclosed the flaw March 4 and updated its advisory Sept. 9 after learning of active exploitation.

CVE-2026-20316 is a static credential vulnerability with a CVSS score of 5.3. It lets an unauthenticated attacker use embedded credentials to access a low-privileged FMC account and sensitive data. The abuse of valid credentials mirrors a broader pattern of attackers exploiting trusted access across enterprise environments.

The three clusters followed different paths. UAT-12197 installed a JSP web shell and malicious JAR file before querying FMC databases for credentials. UAT-11823 established a Netcat reverse shell, stole managed-firewall configurations, and deployed a Cyclops Blink variant.

Talos assesses UAT-11823 as an APT actor with high confidence and says its tooling overlaps with Sandworm. UAT-11988 used CVE-2026-20316 credentials to gather account information and establish SOCKS5 and reverse SSH tunnels into the victim network.

The ransomware operator then probed internal endpoints, deployed tools designed to disable antivirus defenses, and installed Qilin ransomware on selected systems. The FMC attacks follow a separate August campaign in which hackers exploited a Cisco ASA and FTD flaw to force vulnerable firewalls to restart remotely.

Advertisement

Patch, hunt, and contain

Cisco has released hotfixes for both FMC vulnerabilities and lists no workaround. With known vulnerabilities continuing to drive security incidents, teams should treat remediation and compromise assessment as parallel priorities.

Security teams should:

  • Apply available fixes immediately. Confirm affected FMC releases and install Cisco’s appropriate hotfix or fixed software.
  • Restrict FMC management exposure. Keep management interfaces off the public internet where possible and limit access to trusted administrative networks.
  • Deploy and monitor detections. Use Talos-published Snort rules and hunt for web shells, malicious JAR files, Netcat activity, reverse tunnels, SOCKS proxies, and unusual outbound connections.
  • Rotate potentially exposed credentials. Review Active Directory, service, database, and administrative accounts accessible through compromised systems.
  • Hunt for lateral movement. Investigate unusual LDAP/LDAPS, Kerberos, SMB, NetBIOS, and WinRM activity.
  • Audit management activity. Check firewall configuration exports and investigate suspicious package_info.pl activity or modified license.tmp files.
  • Test incident response plans. Confirm teams can isolate compromised management systems, preserve evidence, rotate credentials, investigate downstream hosts, and restore operations safely.

Organizations with indicators of compromise should contact Cisco TAC for recovery guidance. Cisco has also scheduled a Secure Firewall security-hardening release for Sept. 16 covering FMC, ASA, and FTD, although Cisco says publication schedules can change.

Patching blocks the documented entry points, but incident responders still need to determine which credentials, configurations, and internal systems attackers may have reached before remediation.

Read more: A separate China-linked campaign shows the broader risk of compromised network infrastructure, with attackers turning Cisco routers into covert network gateways for access to surrounding environments.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.