Cisco FMC Vulnerabilities Exploited for Credential Theft and Qilin Ransomware Deployment
Cisco has identified two critical vulnerabilities in its Secure Firewall Management Center (FMC) being exploited by threat actors to steal credentials and deploy Qilin ransomware, with one flaw (CVE-2026-20079) rated 10.0 on the CVSS scale. The U.S. CISA has added the most severe vulnerability to its KEV catalog, mandating federal agencies to apply patches by September 12, 2026.
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
*** END OF TRANSMISSION ***