CVE Tools

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker NewsBy The Hacker News

Reported exploitedSecure Firewall Management CenterSandworm

Our summary

Cisco has confirmed that state-sponsored groups, including Sandworm, alongside ransomware operators, are actively exploiting two recently patched vulnerabilities in its Secure Firewall Management Center. The campaigns primarily abuse CVE-2026-20079, a critical authentication bypass flaw allowing remote code execution, along with CVE-2026-20316 to gain unauthorized access and harvest sensitive configuration data. Threat actors have leveraged these flaws to deploy web shells, reverse shells, and the Cyclops Blink implant, ultimately facilitating credential theft and the deployment of Qilin ransomware via living-off-the-land techniques.

Organizations must apply the specific hotfixes released by Cisco for both CVE-2026-20079 and CVE-2026-20316, as CISA has added them to its Known Exploited Vulnerabilities catalog.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store