Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has confirmed that state-sponsored groups, including Sandworm, alongside ransomware operators, are actively exploiting two recently patched vulnerabilities in its Secure Firewall Management Center. The campaigns primarily abuse CVE-2026-20079, a critical authentication bypass flaw allowing remote code execution, along with CVE-2026-20316 to gain unauthorized access and harvest sensitive configuration data. Threat actors have leveraged these flaws to deploy web shells, reverse shells, and the Cyclops Blink implant, ultimately facilitating credential theft and the deployment of Qilin ransomware via living-off-the-land techniques.
Organizations must apply the specific hotfixes released by Cisco for both CVE-2026-20079 and CVE-2026-20316, as CISA has added them to its Known Exploited Vulnerabilities catalog.