logo

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

ID: 43a5cbfe-d577-54d5-b057-f4742b6f05d6

STIX ID: report--43a5cbfe-d577-54d5-b057-f4742b6f05d6

Feed Name: Security Affairs

Threat Score
92/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Pierluigi Paganini

...
...

Cisco Talos reported three distinct clusters exploiting two patched Cisco FMC vulnerabilities (CVE-2026-20079 and CVE-2026-20316) to bypass authentication, deploy JSP web shells and Java-based command executors, steal credentials, install persistent malware such as Cyclops Blink, and ultimately enable Qilin ransomware deployments; the activity involves both criminal and state-linked actors and includes extensive post-compromise reconnaissance, proxying, and AV evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.