Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Summary

Cisco has disclosed that three different threat groups, including those involved in ransomware and state-sponsored attacks, are actively exploiting two previously patched vulnerabilities in their Secure Firewall Management Center (FMC). The exploits target CVE-2026-20079, an authentication bypass flaw, and another vulnerability, enabling attackers to steal credentials and deploy the Qilin ransomware.

IFF Assessment

FOE

The active exploitation of critical vulnerabilities by multiple threat actors, including those deploying ransomware, represents a significant threat to organizations.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.

Defender Context

Defenders need to ensure their Cisco FMC instances are fully patched against the disclosed vulnerabilities to prevent credential theft and ransomware deployment. The active exploitation by multiple threat clusters highlights the urgency of these updates and the need for robust monitoring for signs of compromise.

Read Full Story →