The Cisco FMC Sandworm Qilin breach disclosed on September 9, 2026 by Cisco Talos has pushed a pair of previously known vulnerabilities into active crisis mode, with three distinct attacker clusters now confirmed to be operating inside enterprise firewall management consoles that were never designed to be defended against nation-state intruders. The campaign targets the on-premises edition of Cisco Secure Firewall Management Center, the platform that administrators use to write policies, push configurations, and manage every Cisco firewall appliance in their environment, and it has triggered an emergency directive from the U.S. Cybersecurity and Infrastructure Security Agency.
Why the Cisco FMC Sandworm Qilin breach hits every downstream device
A Secure FMC instance functions as the administrative authority for an entire fleet of Cisco firewalls. It stores managed-device credentials, holds the full policy library, and carries a complete map of the network it oversees. When that single console is compromised, the attacker does not merely obtain one server. They acquire a vantage point from which every firewall under management can be observed, reconfigured, or quietly turned into a passive listening post. The centrality of FMC is precisely what makes the ongoing intrusions so consequential for large enterprises, managed service providers, and government networks that rely on it as their single pane of policy control.
The flaws behind the exploitation
Two separate defects are being chained together to produce full administrative control. The first, CVE-2026-20079, carries a CVSS score of 10.0 and allows an unauthenticated attacker to bypass authentication entirely through a crafted HTTP request against the FMC web interface, then execute commands as root. Cisco first published an advisory for this bug on March 4, 2026, and patches were made available then, yet telemetry indicates attackers were already operating inside unpatched instances by late July. The second flaw, CVE-2026-20316, embeds hard-coded low-privilege credentials into the web interface. CISA added that bug to its Known Exploited Vulnerabilities catalog on July 29, 2026, which gave adversaries a workable entry point more than a month before the more dangerous authentication bypass was publicly confirmed as exploited. The pattern is now familiar: this marks FMC’s third KEV entry in 2026, following a Java deserialization flaw that the Interlock ransomware operation was caught exploiting 36 days before disclosure.
Cluster one: intelligence collection through a web shell
Talos tracks the first cluster as UAT-12197 and characterizes its activity as espionage-oriented rather than disruptive. After leveraging CVE-2026-20079 to obtain an unauthenticated foothold, the operators dropped a JSP-based web shell into the Cisco Security Manager Tomcat webroot, dynamically loading Java classes by Base64-decoding a request parameter so that no obvious bytecode ever touches disk. From there, the cluster introduced a malicious JAR file that served as a simple command executor. Using that tool, the attackers queried FMC’s internal user database and extracted authentication data for every account on the compromised console, handing them credentials that could open doors into every downstream network and device the management center touches.
Cluster two: Sandworm returns with Cyclops Blink
The second cluster, tracked by Talos as UAT-11823, carries the most significant national security weight. Talos attributes this activity to Sandworm, the Russian GRU unit formally identified as Unit 74455 and previously tied to NotPetya and repeated attacks on Ukrainian critical infrastructure, with high confidence based on tooling overlap. The group combined both vulnerabilities to gain access, then abused FMC’s own license-management utility by replacing a temporary file with a self-extracting archive and triggering its execution through the legitimate package_info.pl script, a textbook living-off-the-land technique that bypasses endpoint detection because the offending code is run by a trusted Cisco binary. Two additional bash scripts harvested the full configurations of every managed firewall and staged them for exfiltration, consistent with preparing future intrusions. The final payload deployed was Cyclops Blink, the modular ELF implant previously attributed to Sandworm by the NSA, CISA, the FBI, and the UK’s National Cyber Security Centre following a 2022 campaign against WatchGuard Firebox and ASUS routers.
Cluster three: Qilin affiliate prepares for ransomware deployment
The third cluster is assessed with high confidence to be an affiliate of Qilin, currently the world’s most prolific ransomware-as-a-service operation and a group that has led global attack volume for four consecutive quarters. The same access routes used by the other clusters provide Qilin’s operators with the foothold they need to push ransomware across the firewalls their victims trust to keep them out. Because both cloud-delivered FMC, ASA Software, Firewall Threat Defense Software, and Security Cloud Control remain unaffected, the threat surface is concentrated in organizations running the on-premises management center, and that concentration is what federal authorities moved to address. CISA added CVE-2026-20079 to the KEV catalog and set September 12, 2026 as the mandatory patch deadline for federal civilian agencies, a timeline that leaves private-sector operators with very little room to delay. The Cisco FMC Sandworm Qilin breach is now a live, multi-actor operation, and unpatched management consoles remain the easiest door into some of the most carefully defended networks on the internet.
Source: Cisco Firewall Manager Hacked by Sandworm Espionage Implant and Qilin Ransomware

