Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
11 September 2026
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass