Cisco FMC Compromised by Sandworm and Qilin Ransomware — Three Threat Clusters Confirmed
Cisco Talos has confirmed that three distinct threat clusters — including Russian state-sponsored group Sandworm and a Qilin ransomware affiliate — are actively exploiting two patched vulnerabilities in Cisco Secure Firewall Management Center (FMC). CVE-2026-20079 (CVSS 10.0) gives an unauthenticated remote attacker root access to FMC via an authentication bypass in the web interface. CVE-2026-20316 (CVSS 5.3) provides low-privilege access that can be chained for privilege escalation. The result: management plane compromise of your Cisco firewall estate, with attackers deploying web shells, harvesting credentials, and in one cluster, deploying Qilin ransomware across managed endpoints.
Cluster 1: UAT-12197 — Credential Theft and Database Access
This group exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive command executor on compromised FMC instances. Their objective was credential and authentication data harvesting from internal databases. Web shells provide persistent access to the FMC host, allowing attackers to query managed device configurations and extract authentication tokens. If your FMC is exposed and unpatched, assume credentials for every managed firewall have been collected.
Cluster 2: UAT-11823 — Sandworm Reconnaissance and Cyclops Blink Deployment
This cluster combined both vulnerabilities to deliver a Netcat reverse shell, bash scripts for harvesting managed-device configurations, and a variant of Cyclops Blink — the modular ELF implant previously attributed to Sandworm, the Russian GRU's Main Centre for Special Technologies (GTsST). Cyclops Blink was originally used in the 2022 campaign against WatchGuard firewalls and network storage devices. Its appearance on Cisco FMC represents a documented expansion of Sandworm's targeting into Cisco infrastructure. The implant provides modular reconnaissance, command execution, and persistent C2 capabilities. A Russian military intelligence service now potentially holds root on your firewall management plane.
Cluster 3: UAT-11988 — Qilin Ransomware via Living-off-the-Land
This ransomware operator exploited CVE-2026-20316 for initial access then used legitimate built-in FMC tooling for reconnaissance — classic living-off-the-land technique. They dropped tunneling tools for persistent access, collected credentials, built a target list of endpoints to encrypt, terminated security tools, and deployed Qilin ransomware on selected systems. The use of FMC's own management tooling to propagate ransomware means the attack moves through your firewall management infrastructure, not around it.
So What / Action
The CISA KEV deadline for CVE-2026-20079 is September 12, 2026 — tomorrow. If you run Cisco FMC and have not applied the hotfix, you are accepting root-level risk from two nation-state groups and an active ransomware operator. Priority sequence: apply hotfixes for both CVE-2026-20079 and CVE-2026-20316 now. Check for the license.tmp indicator — if www user invoked package_info.pl against /var/tmp/license.tmp, assume compromise. If found: isolate the FMC, rotate all managed device credentials, review pushed policies for unauthorized changes, and conduct forensic triage before restoring trust to the management plane. Cisco will ship a comprehensive hardening release next week — plan for that upgrade cycle now. 700+ FMC instances are internet-exposed. If yours is one of them, this is no longer a patching decision. It is an incident response decision.

