logo

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

ID: 54dec712-ad66-56c5-9c82-d14f1f05d52b

STIX ID: report--54dec712-ad66-56c5-9c82-d14f1f05d52b

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: Lawrence Abrams

...
...

Cisco Talos reports that two recently patched Cisco Secure Firewall Management Center vulnerabilities (CVE-2026-20079 and CVE-2026-20316) were exploited by three separate intrusion clusters: one attributed to Qilin ransomware affiliates, one linked to a Sandworm-like APT that deployed Cyclops Blink, and a third focused on credential theft; attackers used web shells, modified license files, reverse tunnels/proxies, and legitimate FMC utilities to perform reconnaissance, exfiltrate data, and achieve persistence, and Cisco has released hotfixes and additional hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.