securityaffairs.com 11 Sept 2026, 10:14 UTC

Cisco Firewall Flaws Exploited to Deploy Qilin Ransomware

Cisco Firewall Flaws Exploited to Deploy Qilin Ransomware
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Qilin

THREE threat groups are exploiting two recently patched Cisco Secure Firewall Management Center (FMC) flaws to steal credentials, gain root access, and deploy Qilin ransomware. Cisco Talos attributes three distinct post‑compromise activity clusters to state‑sponsored and crimeware actors, with the main target being CVE-2026-20079, a critical authentication bypass that allows unauthenticated remote access and script execution, potentially enabling root access.

A second flaw, CVE-2026-20316, is used to access data via low‑privilege accounts, and a third weakness can be chained with other FMC vulnerabilities to elevate privileges. The campaign has been linked to Qilin ransomware operations and other state‑sponsored activity.

In the first cluster, CVE-2026-20079 is exploited to drop JSP web shells and a Java Archive‑based command executor in Tomcat webroot directories to harvest credentials and query internal databases.

The second cluster, attributed to the advanced persistent threat actor UAT-11823 (with tooling linked to Sandworm), establishes Netcat reverse shells, harvests device configurations, and installs the Cyclops Blink malware for persistent access, DNS over HTTPS, and packet sniffing, with initial access gained via CVE-2026-20079 or static credentials.

The third cluster involves Qilin operators (UAT-11988) using static credentials, performing domain recon, deploying SOCKS proxies and reverse‑SSH tunnels, and employing AV killers before ransomware deployment. They forward several ports (LDAP 389, LDAPS 636, Kerberos 88, SMB 445, NETBIOS 135, WinRM 5985) and conduct extensive endpoint probing before deploying Qilin on selected machines.

Cisco urges immediate patching with released hotfixes and to update detection rules via Snort SIDs; CISA has added CVE-2026-20079 and CVE-2026-20316 to its KEV catalog with patching guidance by designated deadlines. Authorities stress the need for rapid remediation and monitoring of FMC deployments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline