By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Cisco FMC Flaws Exploited for Ransomware Attacks

Cisco has disclosed that three distinct threat clusters have been actively exploiting two recently patched vulnerabilities within its Secure Firewall Management Center (FMC) software. These exploits have been leveraged for both ransomware deployment and state-sponsored attacks, with a particular focus on credential theft. The vulnerabilities in question are CVE-2026-20079 and CVE-2026-20080. CVE-2026-20079, which carries a critical CVSS score of 10.0, is an authentication bypass vulnerability present in the web interface of the FMC software. This flaw allows an unauthenticated, remote attacker to bypass authentication mechanisms, potentially gaining unauthorized access to the system. The second vulnerability, CVE-2026-20080, is a command injection flaw in the FMC's web interface. This vulnerability enables an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of the FMC. The exploitation of these vulnerabilities has been linked to the Qilin ransomware, a sophisticated strain known for its targeted attacks against organizations across various sectors. Threat actors have utilized the command injection capability to deploy the Qilin ransomware, encrypting victim data and demanding payment for its decryption. Furthermore, the authentication bypass vulnerability has been used to facilitate credential theft, allowing attackers to gain access to sensitive information and potentially move laterally within compromised networks. Cisco's advisory highlights that these exploits have been observed in the wild, indicating active and ongoing malicious activity. The company has urged customers to apply the available patches immediately to mitigate the risks associated with these vulnerabilities. The exploitation of these FMC flaws underscores the persistent threat posed by ransomware groups and state-sponsored actors who continuously seek to exploit unpatched or misconfigured network infrastructure. The ability to bypass authentication and inject commands provides attackers with powerful tools to compromise systems, exfiltrate data, and disrupt operations. The involvement of multiple threat clusters suggests a broad interest in exploiting these specific weaknesses within Cisco's widely deployed firewall management solution. The severity of CVE-2026-20079, with its perfect CVSS score, emphasizes the critical need for prompt patching and robust security practices to prevent unauthorized access and subsequent malicious activities. The successful deployment of Qilin ransomware and the observed credential theft incidents serve as a stark reminder of the financial and operational damages that can result from such exploits. Organizations relying on Cisco FMC are advised to review their security configurations, ensure all systems are updated to the latest secure versions, and implement additional security measures such as multi-factor authentication and network segmentation to enhance their overall security posture against evolving cyber threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.