09-09-2026
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
https://blog.talosintelligence.com/fmc-ongoing-exploitation/
Report completeness: Medium
Actors/Campaigns:
Uat-12197
Uat_11823
Uat_11988
Sandworm
Threats:
Cyclops_blink
Netcat_tool
Lolbin_technique
Qilin_ransomware
Credential_harvesting_technique
Av-killer
Winrm_tool
Impacket_tool
Victims:
Cisco secure firewall management center instances, Compromised organizations
Geo:
Russian
CVEs:
CVE-2026-20079 [Vulners]
CVSS V3.1: 10.0,
Vulners: Exploitation: Unknown
Soft:
- cisco secure_firewall_management_center (7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2)
CVE-2026-20316 [Vulners]
CVSS V3.1: 5.3,
Vulners: Exploitation: True
Soft:
- cisco secure_firewall_management_center (le7.0.9, le7.2.11, le7.3.1.2, le7.4.7, le7.6.5)
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1005, T1018, T1027, T1059, T1059.004, T1078, T1083, T1087.002, T1090.001, T1105, have more...
IOCs:
File: 21
IP: 5
Hash: 3
Soft:
Active Directory, MySQL, ADFS
Algorithms:
base64
Win API:
NETBIOS
Languages:
java, python
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2026/09