Connect with us

Security

Exploiting Cisco FMC Vulnerabilities to Launch Qilin Ransomware Attack and Steal Credentials

Published

on

Cisco recently announced that two critical vulnerabilities in their Secure Firewall Management Center (FMC) have been exploited by threat actors associated with ransomware and state-sponsored attacks.

The first vulnerability, CVE-2026-20079, with a CVSS score of 10.0, allows remote attackers to bypass authentication and gain root access to the operating system. The second flaw, CVE-2026-20316, with a CVSS score of 5.3, enables unauthorized access to sensitive data on affected devices.

Cisco Talos identified three distinct threat clusters exploiting these vulnerabilities. The first cluster, UAT-12197, used CVE-2026-20079 to deploy web shells and command executors to extract user credentials. The second cluster, UAT-11823, exploited both vulnerabilities to deliver malicious scripts and malware, including a variant of the Russian hacking group Sandworm’s Cyclops Blink implant. The third cluster, UAT-11988, conducted a ransomware operation by leveraging CVE-2026-20316 for initial access and deploying ransomware on selected systems.

Cisco recommends applying the hotfixes for CVE-2026-20079 and CVE-2026-20316 and plans to release a comprehensive hardening update for other vulnerabilities soon.

In response to these exploits, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, mandating Federal agencies to patch by a certain date. The second vulnerability, CVE-2026-20316, was also added to the catalog in July 2026.

See also  Lightning Round: Top CVEs, npm Worm Strikes Again, Firefox RCE Alert, M365 Email Intrusion & Beyond

Trending