Build1 publisher3 min readPublished
Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A Cisco researcher found the 10.0 bypass internally; it was fixed in March 2026 with no known exploitation, and Cisco learned of attacks in August.
- Horizon3.ai and TrendAI reported the hard-coded credential flaw, and Cisco fixed it on 29 July 2026, the same day CISA added it to the KEV catalog.
- UAT-11988, assessed as a Qilin affiliate, ran reconnaissance with FMC's built-in tools after logging in, then harvested credentials and delivered ransomware to selected endpoints.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision For this pair, a queue ordered by KEV listing date would have put the 5.3 credential fix ahead of the 10.0 bypass, while a queue ordered by base score puts it last or drops it.
- exposure Compromising one FMC puts every firewall it manages within reach, so rules, logs and pushed configuration across the fleet can all come under attacker control.
- cost Teams that applied the March fix still owe a log review, because one Cisco indicator predates the August date Cisco gives for discovering exploitation.
- constraint Reaching FMC only through a VPN or jump host adds a hop for administrators and removes the direct internet path that a crafted pre-auth HTTP request depends on.
Cisco traces CVE-2026-20079 to a system process that is improperly created at boot. A crafted HTTP request to an unpatched console lets an attacker execute scripts and reach root on the underlying operating system [3]. CVE-2026-20316 is a low-privileged account with a hard-coded credential [5]. A dev.to write-up of the Talos findings says that on its own it grants little, and that chained with the bypass it becomes an entry and reconnaissance path [7].
Talos assesses with high confidence that UAT-11988 is a Qilin ransomware affiliate. It used the static credential to log in and ran reconnaissance with the platform's built-in tools. It then harvested credentials and deployed anti-virus evasion tooling before delivering ransomware to selected endpoints [10].
FMC is the single console that pushes policy to every managed Cisco firewall. The write-up notes that the CVSS vector includes a scope change: an attacker who controls FMC can alter firewall rules, open paths, delete log evidence and push configuration to the fleet [11]. UAT-11823, which Talos assesses shares tooling with Sandworm, chained both flaws and harvested managed firewall configurations. It also installed a Cyclops Blink variant built for credential theft, command execution, file transfer and packet sniffing [9].
The bypass was fixed in March 2026 and the credential flaw on 29 July, about four months later [1]. CISA added the credential flaw to its KEV catalog the day it was fixed [6]. The bypass reached KEV in September [12], so the lower-scored flaw was on the catalog more than a month earlier [2]. A policy that only applies fixes scored above 5.3 would never have applied the July fix, even after KEV listed it and Talos tied it to a ransomware intrusion [3]. For this pair, I think KEV dates were the better way to order the queue [2].
The March fix also shipped under a disclosure that reported no exploitation. Cisco learned of exploitation in August and updated the advisory in September [4]. One Cisco-published indicator of compromise is dated 23 July, earlier than that August discovery [13].
Cisco deserves credit for publishing the retrospective check as a command anyone can paste. In expert mode, run `zgrep "package_info.license" /var/log/messages`. Output pointing at /var/tmp/license.tmp is a compromise indicator that requires a TAC case [14]. That path matches UAT-11823's method of rewriting license.tmp so an installation tool would execute it as root [9]. The guidance also covers unexpected JAR files in the CSM Tomcat webroot [14]. UAT-12197 left a JSP web shell there along with a JAR command executor, then let Cisco's own OmniQuery.pl script pull authentication data from the internal database [8].
Take management interfaces for security appliances off direct internet exposure and reach them through a VPN or jump host. Rotate every credential reachable from FMC, and put the management plane in its own monitoring domain [15]. Rotation matters here because both UAT-11988 and UAT-12197 went after authentication data [8][10].
What to watch
- Whether Cisco moves its stated exploitation start earlier than August, given the published indicator dated 23 July.
- Whether Cisco or CISA revisits the 5.3 score for CVE-2026-20316 now that Talos has tied it, used alone, to a Qilin intrusion.
- Whether the Cyclops Blink variant turns up on managed firewalls as well as on the FMC console itself.