NewsTradingSentimentCalendarCommunityBriefing
Tech

Cisco firewall flaws enable ransomware and state attacks

By Tech Desk · 2026-09-11 · 2 min read
A stylized network firewall device with blinking status lights
Illustration: Tradingbird

Two critical bugs in Cisco firewall management software are being actively exploited by state-sponsored hackers and ransomware groups to steal credentials and seize control of networks.

Cisco has disclosed that three distinct threat clusters are exploiting two recently patched vulnerabilities in its Secure Firewall Management Center (FMC). These flaws allow attackers to bypass authentication entirely, granting them root access to the underlying operating system without needing valid login credentials. The severity of these bugs is high, with the primary vulnerability rated a perfect 10 on the Common Vulnerability Scoring System.

According to reporting from The Hacker News, the attacks are not limited to a single type of adversary. The identified clusters include state-sponsored actors and criminal groups deploying Qilin ransomware. This indicates a broad spectrum of threat actors leveraging the same technical weaknesses to compromise critical network infrastructure, turning defensive tools into entry points for malicious activity.

Authentication bypass enables remote control

The primary flaw, identified as CVE-2026-20079, allows an unauthenticated remote attacker to execute scripts on the device. This effectively removes the need for any user verification, letting the intruder install persistent backdoors and query internal databases for sensitive data. A second vulnerability, CVE-2026-20316, permits low-privilege access that can be escalated to higher levels of control when combined with other weaknesses.

The practical stakes for organizations are severe. Once inside, attackers can harvest configuration files, steal user credentials, and map out the broader network environment. This initial access serves as the foundation for further intrusion, allowing malicious actors to move laterally across systems and identify high-value targets for encryption or data exfiltration.

Distinct groups use varied attack methods

Cisco Talos identified three specific clusters of post-compromise activity. One group, labeled UAT-12197, deployed web shells and command executors to steal authentication data. Another, UAT-11823, used the vulnerabilities to install reverse shells and a modular implant previously linked to the Russian state-sponsored group Sandworm. This implant allows for long-term surveillance and control of the compromised device.

The third cluster, UAT-11988, focused on ransomware deployment. This group used built-in administrative tools to conduct extensive reconnaissance, collect credentials, and build a list of endpoints to encrypt. By terminating security tools and deploying Qilin ransomware, they aimed to maximize disruption and force a ransom payment. The use of legitimate system tools makes this attack harder to detect with traditional security software.

Mandatory patches required for federal agencies

Cisco has released hotfixes for the affected software versions and strongly advises customers to apply them immediately. The company plans to ship a comprehensive hardening release next week to address additional internally discovered issues. Without these updates, systems remain vulnerable to the active exploitation described by security researchers.

The urgency is underscored by the U.S. Cybersecurity and Infrastructure Security Agency, which added the critical vulnerability to its Known Exploited Vulnerabilities catalog. Federal civilian executive branch agencies are required to apply the patches by September 12, 2026. For private sector organizations, the recommendation is clear: delay in patching leaves the door open for the same sophisticated attacks currently targeting state and commercial networks.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories