Article

    Cyber News / Article / Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
    in
    [email protected] (The Hacker News)-about 6 hours ago

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Cisco has revealed thatthree distinct threat clusterslinked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.

    The attacks leverageCVE-2026-20079(CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

    The second flaw under exploitation isCVE-2026-20316(CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.

    Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These include -

    "Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.

    The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedCVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, wasaddedto the KEV catalog in late July 2026.

    Original source

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy… | CVE-DB