Critical Cisco firewall manager flaw powers Qilin attacks

Cisco's firewall management console is the common thread as state-linked spies and the Qilin ransomware crew work the same two bugs.

MedRisk Staff
By
2 Min Read

Two recently patched bugs in Cisco’s Secure Firewall Management Center have drawn three distinct threat groups, according to Talos, the vendor’s threat research arm. The Management Center is the console that governs Cisco firewalls across enterprise and hospital networks.

The primary target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers reach security controls, run scripts, and potentially gain root. CISA added it to the Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch. A second bug, CVE-2026-20316, exposes sensitive data through a low-privilege account and can be chained with other FMC flaws.

Talos tracks three clusters. UAT-12197 drops JSP web shells and a JAR-based command executor, then harvests credentials from internal databases. UAT-11823, whose tooling overlaps the Sandworm-linked set, plants Netcat reverse shells and the modular Cyclops Blink malware for persistent access and packet sniffing. UAT-11988 is Qilin ransomware: static credentials for initial access, domain reconnaissance, SOCKS proxies, reverse-SSH tunnels, then AV killers before encryption.

Qilin has spent 2026 listing healthcare victims, from an Oklahoma clinic chain to European drugmakers. Hospitals that manage firewalls through FMC should apply Cisco’s hotfixes, load the published Snort rules, and hunt for web shells and unexpected outbound tunnels.

Share This Article