Cyber News / Article / Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has revealed thatthree distinct threat clusterslinked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
The attacks leverageCVE-2026-20079(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
The second flaw under exploitation isCVE-2026-20316(CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.
Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These include -
"Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.
The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedCVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, wasaddedto the KEV catalog in late July 2026.
Related articles
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
about 4 hours ago
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
about 5 hours ago
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
about 5 hours ago
You might Also like

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution

