# Cisco says three threat clusters exploiting Secure Firewall Management Center flaws

_Friday, September 11, 2026 at 2:19 AM EDT · Security · Latest · Tier 2 — Notable_

![Cisco says three threat clusters exploiting Secure Firewall Management Center flaws — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJizB5uHZncQAbfKm3-k256bJHufHNcClzKqXH2XK79HlAw8egcuz3abU_gxrTbR2zrWqpMmFcHApBqp5AvC2uox6vEeOlDt1JdRy-A6WAqpFPfVeZ4hM4gp-lCqqY_hIXMu2VVupFLGzbv1sBXLjQGSPlORsnaEdcOqjLJQKAKfDMHJqGY6KY1NZCLth0/s1700-nu-rw-lo-l85-e365/cisco-ransomware.jpg)

Cisco Talos said three clusters of post-compromise activity have exploited two recently patched Secure Firewall Management Center vulnerabilities.

CVE-2026-20079, rated CVSS 10.0, is an authentication bypass in the FMC web interface that can let an unauthenticated remote attacker run script files and gain root on the underlying operating system. UAT-12197 used it to deploy JSP web shells and a Java command executor to pull authentication data and credentials.

UAT-11823 chained both flaws to deliver a reverse shell, configuration-harvesting scripts and a Cyclops Blink variant previously attributed to Sandworm. UAT-11988 used CVE-2026-20316 for initial access, then living-off-the-land tooling to reconnoiter, tunnel, collect credentials and deploy Qilin ransomware. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, with federal patch deadline of September 12, 2026.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html)

---
Canonical: https://techandbusiness.org/newswire/BHy8zWQle8h6NSJBq26r55
Retrieved: 2026-09-12T04:09:09.595Z
Publisher: Tech & Business (techandbusiness.org)
