Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.

The attacks exploited CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static credential vulnerability that allows attackers to log in using a low-privileged account.

According to a new Cisco Talos report, the three clusters used compromised FMC devices to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.

"Talos' analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors," Cisco Talos said.

The company is tracking the clusters as UAT-12197, UAT-11823, and UAT-11988.