Multiple Threat Groups Abuse Cisco Firewall Flaws to Install Web Shells and Deploy Qilin Ransomware
Multiple threat clusters are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) to compromise enterprise networks. The primary flaw, CVE-2026-20079, is a maximum-severity authentication bypass rated CVSS 10.0 that allows an unauthenticated, remote attacker to bypass authentication and execute scripts to obtain root access to the underlying operating system. It is being used together with CVE-2026-20316 (CVSS 5.3), a static-credentials weakness in a low-privileged account that attackers combine with the bypass to deepen their foothold. Organizations running vulnerable, internet-exposed Cisco FMC instances are at immediate risk of credential theft, unauthorized root access, and ransomware deployment.
CVE-2026-20079 stems from an improperly configured boot-time process: a startup routine creates a partial session in the FMC session database, and if no user authenticates after boot, that session persists and can be upgraded into attacker-usable permissions via crafted HTTP requests, requiring no user interaction. Cisco threat intelligence has described three distinct intrusion clusters leveraging one or both flaws. The first placed JSP-based web shells and malicious JAR files and harvested stored credentials to pivot across the network; a second cluster has been attributed to the Russian state-sponsored group Sandworm; and a third deployed Qilin ransomware. The activity therefore spans both nation-state and financially motivated actors rather than criminal ransomware operators alone.
The strategic significance of these attacks extends beyond a typical ransomware incident because the targeted platform controls enterprise firewall infrastructure that protects critical network perimeters, giving attackers visibility into network topology, security policies, and traffic flows. CVE-2026-20079 has been confirmed exploited in the wild and was added to the CISA Known Exploited Vulnerabilities catalog on September 9, 2026, with a federal remediation deadline of September 12, 2026; FIRST EPSS data indicates an approximately 75.8 percent probability of exploitation within the next 30 days. Given the confirmed exploitation and the involvement of multiple sophisticated threat actors, organizations that have not applied the available Cisco updates face a high likelihood of compromise.
Attack Surface
System Management Service, Infrastructure
Tactics
Initial Access, Credential Access, Privilege Escalation, Defense Evasion, Impact
Techniques
- T1190 – Exploit Public-Facing Application
- T1078 – Valid Accounts
- T1068 – Exploitation for Privilege Escalation
- T1552 – Unsecured Credentials
- T1562 – Impair Defenses
- T1486 – Data Encrypted for Impact
SuperPRO's Threat Countermeasures Procedures
- Apply Cisco security patches for CVE-2026-20079 and the second FMC vulnerability to all Secure Firewall Management Center instances immediately
- Review FMC audit logs for unauthorized authentication attempts, unexpected administrative account creation, or configuration changes between the vulnerability disclosure date and patch application
- Reset all credentials stored within or managed by Cisco FMC, including administrator passwords, API keys, and service account credentials used for firewall management
- Implement network segmentation to restrict management plane access to FMC systems, allowing connections only from dedicated jump hosts or privileged access workstations
- Enable multi-factor authentication for all administrative access to Cisco FMC if not already enforced, and verify MFA enrollment for existing accounts
- Deploy detection rules for Qilin ransomware indicators including file encryption activity, suspicious PowerShell execution, and lateral movement from FMC systems to managed firewalls
- Conduct forensic analysis on any FMC instance with internet exposure or suspicious authentication activity to identify potential compromise before ransomware deployment