Cisco FMC Devices Exploited by Ransomware Gangs and State-Sponsored Hackers
Cisco's Secure Firewall Management Center (FMC) devices have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. According to a new Cisco Talos report, the vulnerabilities were used to deploy web shells, steal credentials, create reverse shells and proxies, and in some attacks, deploy Qilin ransomware and Cyclops Blink malware.
The two vulnerabilities, CVE-2026-20079 and CVE-2026-20316, were patched by Cisco earlier this year. However, the company has confirmed that the threats exploited both vulnerabilities to gain access to FMC devices.
One of the intrusion clusters, tracked as UAT-11988, was attributed with high confidence to Qilin ransomware affiliates. The attackers accessed an FMC device using static credentials associated with CVE-2026-20316 and deployed Qilin ransomware on endpoints to encrypt files.