Skip to content

Build1 publisher3 min readPublished

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3
Generated illustration

What happened

  • A Cisco researcher found the 10.0 bypass internally; it was fixed in March 2026 with no known exploitation, and Cisco learned of attacks in August.
  • Horizon3.ai and TrendAI reported the hard-coded credential flaw, and Cisco fixed it on 29 July 2026, the same day CISA added it to the KEV catalog.
  • UAT-11988, assessed as a Qilin affiliate, ran reconnaissance with FMC's built-in tools after logging in, then harvested credentials and delivered ransomware to selected endpoints.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision For this pair, a queue ordered by KEV listing date would have put the 5.3 credential fix ahead of the 10.0 bypass, while a queue ordered by base score puts it last or drops it.
  • exposure Compromising one FMC puts every firewall it manages within reach, so rules, logs and pushed configuration across the fleet can all come under attacker control.
  • cost Teams that applied the March fix still owe a log review, because one Cisco indicator predates the August date Cisco gives for discovering exploitation.
  • constraint Reaching FMC only through a VPN or jump host adds a hop for administrators and removes the direct internet path that a crafted pre-auth HTTP request depends on.

Cisco traces CVE-2026-20079 to a system process that is improperly created at boot. A crafted HTTP request to an unpatched console lets an attacker execute scripts and reach root on the underlying operating system [3]. CVE-2026-20316 is a low-privileged account with a hard-coded credential [5]. A dev.to write-up of the Talos findings says that on its own it grants little, and that chained with the bypass it becomes an entry and reconnaissance path [7].

Talos assesses with high confidence that UAT-11988 is a Qilin ransomware affiliate. It used the static credential to log in and ran reconnaissance with the platform's built-in tools. It then harvested credentials and deployed anti-virus evasion tooling before delivering ransomware to selected endpoints [10].

FMC is the single console that pushes policy to every managed Cisco firewall. The write-up notes that the CVSS vector includes a scope change: an attacker who controls FMC can alter firewall rules, open paths, delete log evidence and push configuration to the fleet [11]. UAT-11823, which Talos assesses shares tooling with Sandworm, chained both flaws and harvested managed firewall configurations. It also installed a Cyclops Blink variant built for credential theft, command execution, file transfer and packet sniffing [9].

The bypass was fixed in March 2026 and the credential flaw on 29 July, about four months later [1]. CISA added the credential flaw to its KEV catalog the day it was fixed [6]. The bypass reached KEV in September [12], so the lower-scored flaw was on the catalog more than a month earlier [2]. A policy that only applies fixes scored above 5.3 would never have applied the July fix, even after KEV listed it and Talos tied it to a ransomware intrusion [3]. For this pair, I think KEV dates were the better way to order the queue [2].

The March fix also shipped under a disclosure that reported no exploitation. Cisco learned of exploitation in August and updated the advisory in September [4]. One Cisco-published indicator of compromise is dated 23 July, earlier than that August discovery [13].

Cisco deserves credit for publishing the retrospective check as a command anyone can paste. In expert mode, run `zgrep "package_info.license" /var/log/messages`. Output pointing at /var/tmp/license.tmp is a compromise indicator that requires a TAC case [14]. That path matches UAT-11823's method of rewriting license.tmp so an installation tool would execute it as root [9]. The guidance also covers unexpected JAR files in the CSM Tomcat webroot [14]. UAT-12197 left a JSP web shell there along with a JAR command executor, then let Cisco's own OmniQuery.pl script pull authentication data from the internal database [8].

Take management interfaces for security appliances off direct internet exposure and reach them through a VPN or jump host. Rotate every credential reachable from FMC, and put the management plane in its own monitoring domain [15]. Rotation matters here because both UAT-11988 and UAT-12197 went after authentication data [8][10].

What to watch

  • Whether Cisco moves its stated exploitation start earlier than August, given the published indicator dated 23 July.
  • Whether Cisco or CISA revisits the 5.3 score for CVE-2026-20316 now that Talos has tied it, used alone, to a Qilin intrusion.
  • Whether the Cyclops Blink variant turns up on managed firewalls as well as on the FMC console itself.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories