Skip to content
feed: live
>_0dayNews
cisco
● Breaking

Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors

Cisco Talos: three threat clusters exploit Cisco FMC CVE-2026-20079. Qilin ransomware deployed; credential theft observed. CISA deadline September 12.

Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·2 min read

Cisco Talos confirmed this week that three distinct threat clusters are actively exploiting vulnerabilities in Cisco Secure Firewall Management Center (FMC), with Qilin ransomware deployment and credential theft both observed. Source: Cisco Talos, via The Hacker News and BleepingComputer.

The platform under attack

FMC is the management plane for Cisco Secure Firewall deployments. Compromising it gives an attacker visibility into every managed policy, rule set, and monitored network segment. That access is valuable before any lateral movement or encryption begins.

The primary confirmed vulnerability is CVE-2026-20079: CVSS 10.0, authentication bypass in FMC and Security Cloud Control (SCC). Unauthenticated, network-reachable, full OS root. CISA added it to the Known Exploited Vulnerabilities catalog on September 9 with a federal remediation deadline of September 12.

Cisco Talos reports a second FMC vulnerability is being exploited alongside CVE-2026-20079. A CVE ID for the second flaw has not been confirmed in available sources at publication. Cisco’s full advisory covers the complete list of affected versions and patch guidance.

Three clusters, three objectives

Cisco Talos documented three separate threat clusters, each with different objectives.

Qilin ransomware. One cluster is deploying Qilin ransomware post-exploitation. FMC access provides a full picture of the managed firewall environment before encryption, which accelerates lateral movement planning. Confidence: Cisco Talos directly attributed this.

State-sponsored espionage. A second cluster is conducting credential theft, with behavior consistent with state-sponsored espionage. Which nation-state is responsible: unconfirmed in available sources.

Third cluster. Cisco Talos identified a third cluster operating concurrently. Objectives not confirmed at publication.

Analysis: three concurrent actors on the same platform with different end goals is consistent with this vulnerability being broadly known across threat actor categories. Ransomware operators and espionage actors do not usually coordinate; they converge when a target is known to be accessible. CVSS 10.0 with no authentication required is that kind of target.

Patch path

Patches were published before exploitation began. CISA’s full advisories on the flaws in this batch are at cisa-kev-sept12-cisco-citrix-fortinet.

Patch path: Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. Internet-accessible FMC management interfaces are the most exposed. Restricting access to a dedicated management VLAN behind jump hosts reduces the reachable attack surface. It does not close the vulnerability.

Federal agencies: the September 12 deadline under BOD 26-04 is binding.

Pattern

This is the third major FMC security event in 2026. CVE-2026-20079 was confirmed exploited on September 9. CVE-2026-20316, a hardcoded credential flaw in FMC’s web interface, reached KEV in July. Two KEV entries on the same management platform inside two months, now with multi-actor exploitation confirmed across ransomware and state-sponsored categories: that is a pattern. Organizations running Cisco Secure Firewall should document and review FMC management-plane exposure, not just patch the current CVE.

Also tracking in the current Cisco vulnerability window: Cisco Nexus 9000 Critical RCE (CVE-2026-20212).

Related CVEs
  • [ CRITICAL ]CVE-2026-20079Cisco FMC Authentication Bypass Enables Root OS Access

Found this useful? Share it.