thehackernews.com 11 Sept 2026, 06:19 UTC

Cisco Firewall Flaws Exploited to Deploy Web Shells and Ransomware

CyberSIXT Evidence Panel

CISCO says three distinct threat clusters tied to ransomware and state‑sponsored activity have been exploiting two recently patched Cisco Secure Firewall Management Center (FMC) vulnerabilities. The first flaw, CVE-2026-20079, is an authentication bypass in the FMC web interface with a CVSS v3 score of 10.0, potentially allowing an unauthenticated remote attacker to bypass authentication and run scripts to obtain root access.

The second, CVE-2026-20316 (CVSS 5.3), could let an unauthenticated, remote attacker log in with a low‑privilege account to access sensitive data and can be chained with other FMC flaws to raise privileges.

Cisco Talos has observed three post‑compromise activity clusters on FMC deployments associated with state‑sponsored groups and crimeware operators, including JSP web shells, a Java ARchive (JAR) based command executor, a Netcat reverse shell, and several credential‑harvesting and configuration‑dumping scripts, with a variant of Cyclops Blink noted in one cluster.

A ransomware operation (UAT‑11988) used CVE-2026-20316 for initial access, then leveraged FMC tooling in a living‑off‑the‑land technique to enumerate the environment, drop tunnelling tools, steal credentials, and deploy Qilin ransomware on targeted endpoints.

Users are urged to apply Cisco’s hotfixes for the affected FMC releases and await a forthcoming hardening release. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, with federal agencies required to apply the patches by 12 September 2026; CVE-2026-20316 was added to KEV in late July 2026.

The developments underscore the need for prompt patching and vigilant monitoring of FMC deployments to mitigate post‑compromise activity and ransomware deployment.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline