MalwareTips News Cisco firewall management flaws exploited in spying and ransomware attacks

Does your workplace use Cisco tools to manage its firewalls?

  • Yes, and I help manage them

    Votes: 1 20.0%
  • Yes, but someone else manages them

    Votes: 1 20.0%
  • I am not sure

    Votes: 1 20.0%
  • We do not use them

    Votes: 2 40.0%

  • Total voters
    5

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
8
23
1
Attackers are actively exploiting two flaws in unpatched Cisco Secure Firewall Management Center software. Organizations using FMC could face stolen credentials, persistent network access and ransomware deployment.


Two flaws provide a route into FMC​

Cisco Talos says CVE-2026-20079 lets an unauthenticated remote attacker bypass login checks, run scripts and gain root access to the underlying operating system. The critical flaw has the maximum CVSS severity score of 10.0.

CVE-2026-20316 allows remote access through a low-privileged account. Its score is lower at 5.3, but attackers can combine it with other FMC weaknesses to gain greater privileges.

  • Apply Cisco's released hotfixes for CVE-2026-20079 and CVE-2026-20316 as soon as possible.
  • Investigate unexpected files named home.jsp, cmd.jar or license.tmp on FMC systems.
  • Review FMC and network logs for connections involving 208.123.119[.]215, an address linked to an attacker-controlled reverse shell.

State-linked malware and credential theft​

In one intrusion cluster, attackers exploited CVE-2026-20079 and installed a web shell, which is a malicious script that provides remote control through a web server. They then used cmd.jar to query internal databases for authentication data and credentials.

A second cluster used a Netcat reverse shell and proxy tools before installing a Cyclops Blink variant. This malware could maintain persistence, harvest credentials, scan networks, capture packets, transfer files and run commands.

Another intrusion led to Qilin ransomware​

Talos assessed with high confidence that a third cluster was a ransomware operator. The attacker used static credentials to enter FMC, mapped the victim's environment, stole credentials and prepared a list of endpoints to encrypt or lock.

The operator also set up proxy and reverse-SSH tunnels for continued access. After probing other systems, the attacker deployed tools designed to disable antivirus products and then installed Qilin ransomware on selected endpoints.