Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
- ID
- 23464
- Status
- summarized
- Published
- 11 Sep 2026, 2:19 PM
- Fetched
- 11 Sep 2026, 4:09 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 11 Sep 2026, 4:10 PM
- Tags
- Audience
- developers
What happened
Cisco disclosed that three threat clusters—two state-sponsored and one crimeware—exploited two recently patched Secure Firewall Management Center (FMC) vulnerabilities (CVE-2026-20079, CVSS 10.0, and CVE-2026-20316, CVSS 5.3) to deploy web shells, reverse shells, credential-harvesting scripts, and Qilin ransomware. One cluster used legitimate FMC tooling for living-off-the-land reconnaissance before encrypting endpoints. Cisco urges customers to apply available hotfixes, with a comprehensive hardening release expected next week.
Why it matters
This is enterprise firewall management software that most builders in this audience do not run or deploy; there is no actionable change for developers, AI/ML practitioners, or SaaS founders unless their organization operates Cisco FMC appliances, in which case patching CVE-2026-20079 immediately is critical.
Discussion angle
Brief mention only: if anyone in the community operates Cisco Secure Firewall infrastructure, confirm hotfixes for CVE-2026-20079 are applied, since active exploitation includes credential theft and Qilin ransomware deployment.