{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aciscosecure_firewall_management_center7.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0.2:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-20079"},{"cvss":5.3,"id":"CVE-2026-20316"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Secure Firewall Management Center","Secure Firewall Threat Defense"],"_cs_severities":["critical"],"_cs_tags":["cisco","fmc","exploitation","cve-2026-20079","cve-2026-20316","ransomware","apt"],"_cs_type":"threat","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco Talos is actively tracking the exploitation of multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) software. Threat actors are chaining CVE-2026-20079, a critical (CVSS 10.0) authentication bypass vulnerability, and CVE-2026-20316, which involves static credentials, to gain initial access and perform lateral movement. Talos has identified three distinct clusters of malicious activity. Cluster UAT-12197 utilizes CVE-2026-20079 to deploy JSP web shells and custom Java-based command executors for credential exfiltration. Cluster UAT-11823, identified as an APT with ties to Sandworm, uses these vulnerabilities to deploy Cyclops Blink malware via a malicious Makeself package. Cluster UAT-11988, assessed as a Qilin ransomware operator, uses static credentials for initial access followed by living-off-the-land (LOTL) techniques to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Defenders must prioritize patching these vulnerabilities, as multiple groups are currently exploiting these flaws in the wild.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial Access: Attackers bypass authentication via CVE-2026-20079 or utilize static credentials (CVE-2026-20316) to access the FMC appliance.\u003c/li\u003e\n\u003cli\u003ePersistence: Attackers place malicious JSP web shells in the CSM Tomcat webroot directory or modify system startup scripts (e.g., /etc/init.d/) to maintain access.\u003c/li\u003e\n\u003cli\u003eExecution: Attackers abuse the legitimate package_info.pl utility to execute malicious files (e.g., license.tmp) or custom JAR files (e.g., cmd.jar) with root privileges.\u003c/li\u003e\n\u003cli\u003ePrivilege Escalation: Exploitation of system utilities allows actors to transition from initial low-privileged access to root-level command execution on the underlying OS.\u003c/li\u003e\n\u003cli\u003eDiscovery: Attackers perform system and network reconnaissance, including directory listing, credential harvesting via OmniQuery.pl, and internal database queries.\u003c/li\u003e\n\u003cli\u003eCommand and Control: Deployment of Netcat-based reverse shells and SOCKS proxy/reverse-SSH tunneling tools to maintain communication with actor infrastructure.\u003c/li\u003e\n\u003cli\u003eImpact: Final stages include exfiltration of configurations, deployment of modular implants like Cyclops Blink, or deployment of Qilin ransomware to target endpoints.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain full administrative control over the FMC appliance. Observed impacts include the exfiltration of sensitive configuration data, deployment of modular botnet malware, and large-scale ransomware encryption of downstream enterprise networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eApply the security patches provided by Cisco for CVE-2026-20079 and CVE-2026-20316 immediately.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unauthorized files in the CSM Tomcat webroot directory.\u003c/li\u003e\n\u003cli\u003eAudit the use of system-level utilities like package_info.pl and OmniQuery.pl for anomalous command-line arguments.\u003c/li\u003e\n\u003cli\u003eBlock communication with the known C2 IP 208.123.119.215 at the network perimeter.\u003c/li\u003e\n\u003cli\u003eMonitor for processes spawning unexpected shells or network utilities such as nc (Netcat).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T12:55:02Z","date_published":"2026-09-09T18:47:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cisco-fmc-exploitation/","summary":"Multiple threat actors, including state-sponsored groups and ransomware operators, are actively exploiting authentication bypass (CVE-2026-20079) and static credential (CVE-2026-20316) vulnerabilities in Cisco Secure Firewall Management Center to achieve root-level code execution and deploy malware.","title":"Active Exploitation of Cisco Secure Firewall Management Center","url":"https://feed.craftedsignal.io/briefs/2026-09-cisco-fmc-exploitation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cisco:secure_firewall_management_center:7.1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}