Three distinct threat groups, including state-sponsored actors and the Qilin ransomware gang, are actively exploiting two critical vulnerabilities in Cisco Secure Firewall Management Center to compromise enterprise networks.
Key Points
- Cisco Talos identified three attack clusters targeting CVE-2026-20079, a critical authentication bypass, and CVE-2026-20316, which allows unauthorized data access.
- Attackers are deploying web shells, custom command executors, and the Cyclops Blink modular malware to maintain persistent access and exfiltrate credentials.
- The Qilin ransomware group (UAT-11988) uses these flaws to conduct domain reconnaissance, establish SOCKS proxies, and deploy AV-killing tools before launching ransomware.
- CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, mandating that U.S. federal agencies apply necessary patches by September 12, 2026.
- Cisco advises administrators to immediately install available hotfixes and update Snort detection rules to mitigate ongoing exploitation attempts.