Cisco firewall management flaws exploited by multiple threat groups

Cisco Talos identified two vulnerabilities in Secure Firewall Management Center that were exploited by three separate threat clusters, including ransomware affiliates and state-sponsored actors. The attackers used the flaws to deploy web shells, steal credentials, create reverse shells, and in some cases deploy Qilin ransomware and Cyclops Blink malware. Cisco has released hot fixes for both flaws and is urging customers to install them immediately.
The two flaws carry distinct severity ratings, with the authentication bypass scoring a perfect 10.0, while the static credential issue scores 5.3 but is deemed high risk due to its potential for privilege escalation when chained with other bugs. Cisco has issued emergency hot fixes and plans a broader hardening patch next week.
One cluster, tied to Qilin ransomware, leveraged legitimate management tools to map internal networks, harvest credentials, and stage data for exfiltration before deploying encryption. Another cluster, linked to Sandworm, used a modified license file to establish a reverse shell and ultimately delivered Cyclops Blink malware. A third cluster, UAT-12197, was also observed but not detailed.
Organizations relying on Cisco's firewall management platform could face severe operational disruption if patches are not applied promptly. The combination of ransomware deployment and state-sponsored espionage suggests that both financial and national security interests are at risk. Enterprises, government agencies, and critical infrastructure operators may experience data theft, service outages, or prolonged recovery periods. The exploitation of legitimate management tools underscores how deeply trusted administrative interfaces can become attack vectors, potentially eroding confidence in network defense systems.