Three Threat Clusters Exploit Critical Vulnerabilities in Cisco Firewall Management Center

Cisco Talos identified the activity under three tracking identifiers: UAT-12197, UAT-11823 and UAT-11988. The clusters used different tools and pursued different objectives rather than operating as a single campaign.
The campaigns involved highly specific tooling: UAT-12197 deployed web shells and the cmd.jar file to steal credentials through OmniQuery; UAT-11823, linked to Sandworm, deployed Cyclops Blink; and Qilin-associated UAT-11988 used the vulnerabilities for reconnaissance and credential harvesting.
Talos observed attackers combining CVE-2026-20079 and CVE-2026-20316 in the same intrusion chain, using the authentication bypass and static credentials together to broaden access beyond the initial foothold.
The root cause of CVE-2026-20079 is an improper system process created when FMC boots; crafted HTTP requests sent to an unpatched device can exploit that process to run commands with root privileges.
In one documented credential-theft sequence, attackers placed a JSP web shell in the CSM Tomcat webroot and ran cmd.jar to query the FMC database for usernames and authentication data using OmniQuery.
Three separate threat groups are actively exploiting two critical vulnerabilities in Cisco Secure Firewall Management Center to steal credentials, plant malware and support ransomware attacks. Cisco Talos identified the campaigns using flaws CVE-2026-20079 and CVE-2026-20316, which allow attackers to bypass authentication and execute commands with root-level access. One vulnerability carries a perfect CVSS score of 10.0, making it among the most dangerous flaws in enterprise firewall software.
The attackers linked to Qilin ransomware, Russia's Sandworm unit and a credential-theft operation have used compromised FMC systems to deploy web shells, steal login data and tunnel into networks. Because FMC centrally controls firewall policies across entire organizations, a single breach can give attackers strategic access to protected environments. Security Affairs reports that organizations must apply available patches immediately and scan systems for signs of compromise.
CVE-2026-20079 scored a 10.0 on the CVSS severity scale because it requires no authentication to exploit. The flaw stems from an improper system process that FMC creates when it boots. Attackers send specially crafted HTTP requests to unpatched devices, and those requests run commands with root privileges — the highest level of system access. Cisco Talos says this single vulnerability opens a direct path into networks without needing user credentials or system access.
The second flaw, CVE-2026-20316, exposes static credentials stored in the system. These credentials grant access to a low-privileged account, but attackers often chain both vulnerabilities together in the same attack. They use the authentication bypass to get in, then leverage the exposed credentials to expand their foothold and access broader system functions.
Cisco Talos tracked the campaigns under three identifiers: UAT-12197, UAT-11823 and UAT-11988. Each group uses different tools and tactics. One cluster deployed web shells and a tool called cmd.jar to steal credentials from the FMC database using OmniQuery queries. Another, linked to Sandworm, deployed Cyclops Blink malware. The third, associated with Qilin ransomware, used the vulnerabilities for reconnaissance and credential harvesting.
The separate tracking suggests these are not coordinated attacks but rather independent threat groups exploiting the same critical flaws. Security Affairs reports that in one documented sequence, attackers placed a JSP web shell in the FMC Tomcat webroot and ran cmd.jar to query usernames and authentication data. The compromised systems became staging grounds for lateral movement into broader corporate networks.
Cisco Secure Firewall Management Center is a central hub. It manages firewall policies and devices across entire organizations. When attackers compromise FMC, they can modify firewall rules, inspect traffic and redirect network flows. Security Affairs notes that this central position makes FMC a high-value target — breaching it provides a strategic foothold that persists even after patches are released to individual firewalls.
Attackers used compromised FMC systems to deploy reverse shells for remote access, steal credentials, conduct network reconnaissance and tunnel through firewalls into protected segments. At least one campaign supported ransomware deployment, converting the management system into a launchpad for broader extortion attacks. Cisco and U.S. security agencies are urging organizations to apply hotfixes immediately and investigate any signs of unauthorized FMC access.
Publishers
15
Articles
10
Reach
25