Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
AI Summary
Multiple threat actor clusters have exploited two critical vulnerabilities in Cisco's Secure Firewall Management Center (FMC) to gain unauthorized access, steal credentials, and deploy ransomware. CVE-2026-20079, a critical authentication bypass flaw (CVSS 10.0), allowed unauthenticated remote attackers to execute scripts and gain root access. CVE-2026-20316, a lower-severity flaw, enabled access via a low-privilege account and was used in conjunction with other vulnerabilities for privilege escalation. Three distinct post-compromise activity clusters were identified: UAT-12197 deployed JSP web shells and JAR-based command executors; UAT-11823 delivered Netcat reverse shells and a Cyclops Blink variant; and UAT-11988, a ransomware operation, used living-off-the-land techniques to deploy Qilin ransomware.
AI-extracted · verify before operational use