MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-10 · via BleepingComputer

Cisco firewall management flaws exploited by multiple threat groups

Image via BleepingComputer
Image via BleepingComputer

Cisco Talos identified two vulnerabilities in Secure Firewall Management Center that were exploited by three separate threat clusters, including ransomware affiliates and state-sponsored actors. The attackers used the flaws to deploy web shells, steal credentials, create reverse shells, and in some cases deploy Qilin ransomware and Cyclops Blink malware. Cisco has released hot fixes for both flaws and is urging customers to install them immediately.

Expanded Detail

The two flaws carry distinct severity ratings, with the authentication bypass scoring a perfect 10.0, while the static credential issue scores 5.3 but is deemed high risk due to its potential for privilege escalation when chained with other bugs. Cisco has issued emergency hot fixes and plans a broader hardening patch next week.

One cluster, tied to Qilin ransomware, leveraged legitimate management tools to map internal networks, harvest credentials, and stage data for exfiltration before deploying encryption. Another cluster, linked to Sandworm, used a modified license file to establish a reverse shell and ultimately delivered Cyclops Blink malware. A third cluster, UAT-12197, was also observed but not detailed.

Context

Organizations relying on Cisco's firewall management platform could face severe operational disruption if patches are not applied promptly. The combination of ransomware deployment and state-sponsored espionage suggests that both financial and national security interests are at risk. Enterprises, government agencies, and critical infrastructure operators may experience data theft, service outages, or prolonged recovery periods. The exploitation of legitimate management tools underscores how deeply trusted administrative interfaces can become attack vectors, potentially eroding confidence in network defense systems.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
Automated AI agents drive mass exploitation of PaperCut vulnerabilities · Cybersecurity
Chrome Vulnerability Actively Exploited in the Wild Triggers Emergency Update · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers.” Browse more stories.