1. Basic Information
- Original Source: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
- Publisher: BleepingComputer
- Publication Date: 2026-07-29T17:35:00-04:00
- Update Date: 2026-09-10
- Severity: Critical
- Reason for Severity: Confirmed real-world damage where root compromise of a perimeter management device led to internal network tunneling, reaching both state-sponsored backdoors and ransomware.
- Related Sources: Cisco Talos technical report, BleepingComputer campaign update, Cisco CVE-2026-20316 advisory, Cisco CVE-2026-20079 advisory
- Reason for Update: Updated because Cisco Talos published details on real-world damage from three intrusion clusters, CVE chaining, web shells, internal tunneling, Qilin, Cyclops Blink, and credential theft.
2. Executive Summary
Cisco Talos identified three intrusion clusters abusing authentication bypass and static credentials in Secure FMC, and published the attack paths leading to Qilin ransomware or Cyclops Blink via web shells, credential theft, and SOCKS5/SSH tunnels.
3. Attack Flow
Cisco Secure FMC CVE-2026-20079 and CVE-2026-20316: Three Intrusion Clusters Leading to Qilin and Cyclops Blink
- The attacker breaches the FMC using the CVE-2026-20079 authentication bypass or CVE-2026-20316 static credentials.
- The attacker gains root command execution using JSP web shells, cmd.jar, license.tmp, or package_info.pl.
- The attacker collects the FMC database, managed device configurations, AD and MySQL credentials, and domain and host information.
- The attacker connects from the FMC to the internal network using Netcat, Python SOCKS5, or reverse SSH.
- One cluster deploys Cyclops Blink to the FMC, while another cluster deploys Qilin to endpoints for encryption.
4. Attacker Position and Execution Location
- Unauthenticated attackers with network reachability to the FMC management interface, or remote attackers using static credentials.
5. Visibility for Victims and Administrators
Victims
- Compromise of the FMC itself may remain hidden until configuration changes on managed firewalls or encryption of internal endpoints become apparent.
Administrators
- Clues include JSP files in the Tomcat webroot, cmd.jar, license.tmp, package_info.pl, exposed staging files, Netcat/SOCKS5/SSH tunnels, and abnormal database queries.
6. Success and Failure Conditions
Success Conditions
- Hotfixes are not applied to vulnerable FMC versions.
- The management interface is reachable from the attack source.
- The FMC has broad network reachability and credential read privileges to internal identity providers, servers, and endpoints.
Failure Conditions and Risk Mitigation
- Apply Cisco hotfixes and additional hardening for both CVEs.
- Restrict the FMC management interface to a dedicated management network and allowlist.
- Minimize internal and external communication from the FMC, service account privileges, and exposed files.
7. What Happens Upon Success
- Root code execution and web shell persistence on the FMC
- Theft of managed device configurations, authentication data, and AD/MySQL credentials
- Persistent backdoor via Cyclops Blink
- Internal endpoint encryption via Qilin
8. Observable Logs
- None.
Proxy / SWG / DNS
- Netcat, SSH, tool downloads, and archive uploads from the FMC to unknown IPs.
Endpoint / EDR
- Execution of Impacket, Invoke-TheHash, EDR killers, and Qilin on internal endpoints.
Identity / IdP
- Use of static built-in accounts, abnormal authentication to AD service accounts, and hash reuse.
SaaS / Cloud
- None.
Network
- New connections from the FMC to LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM, along with SOCKS5 and reverse SSH tunnels.
9. Attack Success Determination
- Malware Execution or Authentication Success Confirmed: Talos confirmed active exploitation of both CVEs, root command execution, and web shell/reverse shell creation.
- Data Theft or Session Compromise Confirmed: Confirmed collection and exfiltration of FMC database authentication data, managed device configurations, and AD/MySQL credentials.
- Subsequent Compromise Confirmed: Confirmed deployment of Cyclops Blink, and deployment and encryption with Qilin on internal endpoints in a separate cluster.
10. Investigation Playbook
Starting Point
- Begin the investigation when vulnerability exploitation, abnormal authentication, IOCs, or behaviors described in this text are detected for target products or accounts.
Initial Verification
- Check assets, versions, configurations, exposure scope, event timing, source IP, and target ID.
- Separate the observation scope indicated by sources from evidence confirmed within your own organization.
Endpoint
- Review process lineage, file creation, permission changes, persistence, and credential access chronologically for related processes.
Identity / Cloud
- Check for authentication method changes, token usage, and cloud data access associated with the same user, source, or session.
Subsequent Investigation
- Expand the investigation scope from the initial compromise to internal reconnaissance, lateral movement, C2, archive creation, and data transfer.
Containment
- Isolate or restrict public access to the target and apply patches. If compromise is confirmed or suspected, revoke and replace related secrets such as sessions, keys, and passwords.
Judgment
- Record as an attack attempt if only requests or contact with IOCs are found; record as the corresponding success stage if evidence of execution, authentication, or data access exists.
11. Defense and Detection Ideas
Single Event
- Netcat, SSH, tool downloads, and archive uploads from the FMC to unknown IPs.
- Execution of Impacket, Invoke-TheHash, EDR killers, and Qilin on internal endpoints.
- Use of static built-in accounts, abnormal authentication to AD service accounts, and hash reuse.
- None.
Time-Series Correlation
- Correlate short-term abnormal authentication, configuration changes, reconnaissance, massive access, and outbound communication originating from the same entity.
Threat Hunting
- Retrospectively search for processes, authentication events, network traffic, and configuration changes representing the same attack steps, without relying solely on the IOCs in this text.
Log Gaps
- Verify target log enablement, time synchronization, retention periods, and correlation keys across endpoints, cloud environments, and perimeter devices.
Priority Countermeasures
- Apply Cisco hotfixes and additional hardening for both CVEs.
- Restrict the FMC management interface to a dedicated management network and allowlist.
- Minimize internal and external communication from the FMC, service account privileges, and exposed files.
12. Facts / Inference / Hypothesis
Facts
- CVE-2026-20079 is a CVSS 10.0 vulnerability allowing unauthenticated remote attackers to bypass FMC authentication and execute root scripts. CVE-2026-20316 is a CVSS 5.3 issue involving static credentials for built-in low-privilege accounts, which can be chained with other vulnerabilities.
- UAT-12197 exploited CVE-2026-20079 to place a JSP web shell in the CSM Tomcat webroot, queried the internal database via cmd.jar, and stole authentication data.
- UAT-11823 gained entry via CVE-2026-20079 or static credentials, replaced license.tmp with a Makeself package containing a Netcat reverse shell, and executed it as root using package_info.pl.
- UAT-11823 archived and exfiltrated managed device configurations and deployed a Cyclops Blink variant with tooling overlapping Sandworm. Talos has high confidence in attributing this to UAT-11823, with a tooling overlap relationship to Sandworm.
- UAT-11988 performed internal reconnaissance using built-in FMC tools via static credentials, staged AD service accounts, MySQL credentials, and domain information into an exposed file, and retrieved it via an HTTP GET request.
- UAT-11988 tunneled LDAP, LDAPS, Kerberos, SMB, NetBIOS, and WinRM traffic using a Python SOCKS5 proxy and a reverse SSH tunnel, and deployed Qilin ransomware to endpoints after using Impacket, Invoke-TheHash, and EDR killers.
Inference
- Investigation and detection methods for each environment were considered based on attack behaviors confirmed in public information. Actual evidence obtained depends on log settings and retention periods.
Hypothesis
No additional hypotheses. Unconfirmed items are listed under "Unknowns and Further Investigation."
13. MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application (Confidence: High): Exploits FMC authentication bypass and static credentials.
- T1505.003 Server Software Component: Web Shell (Confidence: High): Places a JSP web shell in the Tomcat webroot.
- T1572 Protocol Tunneling (Confidence: High): Tunnels internal protocols using SOCKS5 and reverse SSH.
- T1555 Credentials from Password Stores (Confidence: High): Collects FMC database, AD service account, and MySQL credentials.
- T1486 Data Encrypted for Impact (Confidence: High): Qilin encrypts internal endpoints.
14. Unknowns and Further Investigation
- Direct identity correlation between UAT-11823 and Sandworm.
- The number of victim organizations for each cluster and the scope of use for stolen configurations and credentials.
- Details of unannounced vulnerabilities included in Cisco's additional hardening.
15. Impact on SOCs and Organizations
Because the FMC manages numerous firewalls and holds connection information and credentials for internal networks, the compromise of a single device leads to widespread lateral movement. Organizations should verify not only hotfixes but also management interface segregation, least privilege for FMC service accounts, and restricted communication from the FMC to LDAP, SMB, WinRM, and other services. SOCs must track web shells and package execution on the FMC alongside hash authentication, EDR termination, and encryption on internal endpoints as a single incident.
16. Summary by Role
- SOC: Correlates FMC JSP files, cmd.jar, license.tmp, database queries, and tunnels with internal hash authentication, EDR termination, and Qilin activity.
- Administrator: Applies both hotfixes and hardening, and minimizes the management interface, service accounts, and internal/external communication from the FMC.
- User: Perimeter device attacks require no user action. Immediately report any widespread service disruptions on managed services or file encryption.
Top comments (0)