www.darkreading.com 14 Sept 2026, 21:37 UTC

Russia-linked hackers exploit Cisco firewall flaws to deploy Cyclops Blink

Russia-linked hackers exploit Cisco firewall flaws to deploy Cyclops Blink
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

A likely Russia-linked threat actor is exploiting two vulnerabilities in Cisco Secure Firewall Management Centre (FMC) to deploy an updated version of the Cyclops Blink malware. Sophos and Cisco Talos identified the activity, while Sophos attributed it with high confidence to Russia-nexus actors and only moderate confidence to Sandworm, citing no conclusive evidence directly linking the group to the 2026 deployments.

The vulnerabilities are CVE-2026-20079, a maximum-severity authentication bypass allowing unauthenticated remote code execution and root access, and CVE-2026-20316, a CVSS 5.3 flaw that permits low-privilege remote access and can be combined with earlier FMC flaws for privilege escalation. Attackers reportedly use the chain to install a Netcat-based reverse shell and proxy before deploying Cyclops Blink.

Cisco said it had evidence of exploitation in the wild and released hotfixes for both flaws in the week before 14 September 2026. It strongly urged affected organisations to apply them immediately, ahead of a broader hardened FMC release planned for later that week. Cisco also reported two other exploitation clusters: UAT 12197, which uses CVE-2026-20079 to install web shells and a Java command-execution tool for credential theft, and UAT 11988, which uses CVE-2026-20316 to distribute Qilin ransomware.

The new Cyclops Blink variant runs on 64-bit x86-64 Linux rather than the original 32-bit PowerPC architecture, uses generic SysV persistence, and adds network scanning, selective packet capture and collection of password hashes, process command lines, CPU details and configuration data.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline