AUTO-UPDATED

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three distinct threat groups, including state-sponsored actors and the Qilin ransomware gang, are actively exploiting two critical vulnerabilities in Cisco Secure Firewall Management Center to compromise enterprise networks.

Key Points

  • Cisco Talos identified three attack clusters targeting CVE-2026-20079, a critical authentication bypass, and CVE-2026-20316, which allows unauthorized data access.
  • Attackers are deploying web shells, custom command executors, and the Cyclops Blink modular malware to maintain persistent access and exfiltrate credentials.
  • The Qilin ransomware group (UAT-11988) uses these flaws to conduct domain reconnaissance, establish SOCKS proxies, and deploy AV-killing tools before launching ransomware.
  • CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, mandating that U.S. federal agencies apply necessary patches by September 12, 2026.
  • Cisco advises administrators to immediately install available hotfixes and update Snort detection rules to mitigate ongoing exploitation attempts.

Why it Matters

These vulnerabilities provide attackers with high-level access to critical network infrastructure, potentially leading to full system compromise and ransomware deployment. Organizations using Cisco Secure Firewall Management Center must prioritize patching to prevent unauthorized access and protect sensitive internal data from sophisticated threat actors.
Securityaffairs.com Published by Pierluigi Paganini
Read original