Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

    Date: 09/10/2026

    Severity: High

    Summary

    Active exploitation of Cisco Secure Firewall Management Center (FMC) vulnerabilities CVE-2026-20079 and CVE-2026-20316, enabling authentication bypass, unauthorized access, and privilege escalation. Threat clusters deployed web shells, reverse shells, proxy tools, Cyclops Blink, and credential-harvesting capabilities. A separate ransomware operation used living-off-the-land (LOTL) techniques, network reconnaissance, tunneling, credential theft, and ultimately deployed Qilin ransomware. 

    Indicators of Compromise (IOC) List 

    IP Address

    43.204.2.142

    89.34.96.56

    208.123.119.215

    104.218.165.253

    91.214.78.118

    Hash

    B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d

    Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e

    6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("43.204.2.142","104.218.165.253","89.34.96.56","208.123.119.215","91.214.78.118") or srcipaddress IN ("43.204.2.142","104.218.165.253","89.34.96.56","208.123.119.215","91.214.78.118")

    Detection Query 2 :

    sha256hash IN ("B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d","6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461","Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e")

    Reference: 

    https://blog.talosintelligence.com/fmc-ongoing-exploitation/   


    Tags

    WebShellreverse shellCredential Harvestingliving off the land (LOTL)QilinMalwareVulnerabilityExploitationRansomwareCVE-2026

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags