← Back to FeedCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
CVE-2026-20079CVE-2026-20316
September 11, 2026 · The Hacker News · Severity: CRITICAL
Cisco has confirmed that three separate threat clusters — including both ransomware operators and state-sponsored hackers — are actively exploiting two flaws in Cisco Firepower Management Center to steal credentials and deploy the Qilin ransomware payload. The vulnerabilities bypass authentication on the security management appliance, giving attackers administrative control over the organization's own defense infrastructure.
📌 **Analyst Note:** When vulnerabilities in security appliances are exploited, the defender loses their visibility advantage. In this case, attackers are compromising the very platform that should detect them — making this one of the highest-risk vulnerability disclosures this quarter.
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges. Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These include - UAT-12197 , which has exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor to query internal databases and obtain user authentication data and credentials UAT-11823 , which has exploited both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell, two bash scripts to harvest managed-device configurations, and a variant of Cyclops Blink , a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm UAT-11988 , a ransomware operation that has exploited CVE-2026-20316 for initial access and then used legitimate built-in FMC tooling as part of a living-off-the-land (LotL) attack to conduct extensive reconnaissance of the victim's environment, drop tunneling tools to maintain network access, collect credentials, build a target list of endpoints to encrypt, terminate security tools, and deploy Qilin ransomware on selected systems. "Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week. The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, was added to the KEV catalog in late July 2026. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Key Takeaways
- Cisco disclosed that three distinct threat clusters — including ransomware gangs and state-sponsored actors — are actively exploiting CVE-2026-20079 and CVE-2026-20316 in Cisco Firepower Management Center to steal credentials and deploy Qilin ransomware.
- The vulnerabilities allow attackers to bypass FMC authentication mechanisms and gain administrative control over Cisco security appliances, effectively turning the defense infrastructure against the organization.
- Organizations running Cisco FMC should treat this as an emergency patching priority given the confirmed active exploitation by multiple independent threat groups with different objectives.