Cisco FMC Vulnerabilities Exploited by Multiple Threat Actors
Cisco's Firewall Management Center (FMC) has become a target for cyberattacks, with three different threat actors exploiting vulnerabilities to steal credentials and deploy Qilin ransomware.
The two recently patched vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have been exploited by state-sponsored hackers and criminal groups worldwide. The first vulnerability, CVE-2026-20079, has a CVSS score of 10.0 - the maximum severity score possible - and allows an unauthorized remote attacker to bypass authentication and execute scripts on an affected device.
The second vulnerability, CVE-2026-20316, has a CVSS score of 5.3 and allows an unauthorized remote attacker to log in to an affected device using a low-privilege account, gaining access to sensitive data.
Cisco advises customers to immediately apply the hotfixes that have already been released for the affected software versions and implement additional security measures, such as monitoring FMC logs, implementing least privilege accounts, network segmentation, and multi-factor authentication.