Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Brief
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware.
Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079 , a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run scripts and potentially gain root access. Attackers also exploit CVE-2026-20316 to access sensitive data through a low-privilege account.
The second flaw can be chained with other FMC vulnerabilities to increase privileges.
Cisco linked the attacks to ransomware operations, including Qilin , as well as state-sponsored activity.
“Talos’ analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors, as described below.”
