CVE Tools
Back to feed
Exploited in the wild Secure Firewall Management Center Sandworm ransomware Cisco nation-state

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Cisco has confirmed that state-sponsored groups, including Sandworm, alongside ransomware operators, are actively exploiting two recently patched vulnerabilities in its Secure Firewall Management Center. The campaigns primarily abuse CVE-2026-20079, a critical authentication bypass flaw allowing remote code execution, along with CVE-2026-20316 to gain unauthorized access and harvest sensitive configuration data. Threat actors have leveraged these flaws to deploy web shells, reverse shells, and the Cyclops Blink implant, ultimately facilitating credential theft and the deployment of Qilin ransomware via living-off-the-land techniques.

Organizations must apply the specific hotfixes released by Cisco for both CVE-2026-20079 and CVE-2026-20316, as CISA has added them to its Known Exploited Vulnerabilities catalog.