Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Reported exploitedSecure Firewall Management CenterSandwormOur summary
Cisco has confirmed that state-sponsored groups, including Sandworm, alongside ransomware operators, are actively exploiting two recently patched vulnerabilities in its Secure Firewall Management Center. The campaigns primarily abuse CVE-2026-20079, a critical authentication bypass flaw allowing remote code execution, along with CVE-2026-20316 to gain unauthorized access and harvest sensitive configuration data. Threat actors have leveraged these flaws to deploy web shells, reverse shells, and the Cyclops Blink implant, ultimately facilitating credential theft and the deployment of Qilin ransomware via living-off-the-land techniques.
Organizations must apply the specific hotfixes released by Cisco for both CVE-2026-20079 and CVE-2026-20316, as CISA has added them to its Known Exploited Vulnerabilities catalog.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.