Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
AI Summary
Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software: CVE-2026-20079, a critical authentication bypass flaw, and CVE-2026-20316, which allows login via a low-privileged account. Three distinct threat clusters have been identified: UAT-12197 deployed a JSP web shell and a JAR-based command executor; UAT-11823, linked to Sandworm, used CVE-2026-20079 and CVE-2026-20316 to deploy Cyclops Blink malware via a Netcat reverse shell; and UAT-11988, a Qilin ransomware operator, leveraged static credentials to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Customers are urged to apply available patches immediately.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | Details → |
| Filename | home.jsp | Details → |
| SHA-256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | Details → |
| Filename | cmd.jar | Details → |
| IP | 89[.]34[.]96[.]56 | Details → |
| IP | 208[.]123[.]119[.]215 | Details → |
| IP | 104[.]218[.]165[.]253 | Details → |
| IP | 91[.]214[.]78[.]118 | Details → |
| SHA-256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | Details → |
| IP | 43[.]204[.]2[.]142 | Details → |