Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says three threat clusters exploited two newly patched Cisco Secure Firewall Management Center flaws, leading to web shells, credential theft, reverse shells, and proxy deployment. The attacks were linked to Qilin ransomware, Cyclops Blink, and activity overlapping with the Sandworm APT group. #CVE-2026-20079 #CVE-2026-20316 #Qilin #CyclopsBlink #Sandworm #CiscoTalos

Keypoints

  • Three threat clusters exploited Cisco Secure FMC vulnerabilities in separate intrusion campaigns.
  • CVE-2026-20079 enabled unauthenticated remote access and root-level script execution.
  • CVE-2026-20316 allowed login with static low-privileged credentials.
  • One cluster deployed Qilin ransomware after stealing credentials and mapping the internal network.
  • Another cluster deployed Cyclops Blink, while a third used web shells and JAR files to steal authentication data.

Read More: https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/