Cisco Warns of State and Criminal Hackers Exploiting Firewall Management Center Vulnerabilities
Cisco has issued a warning about two vulnerabilities in its Secure Firewall Management Center software that are being exploited by state and criminal hackers.
The Russian Sandworm group and Qilin ransomware gang are among those targeting the bugs, according to Cisco's threat intelligence arm, Talos.
Talos said it has identified three clusters of malicious activity: one involving credential theft via a Java Archive-based command executor; another likely linked to the Russian Sandworm group, which is using tools such as Makeself and Netcat to gain access and deploy malware; and a third cluster thought to be related to Qilin ransomware.
Cisco has released hotfixes for affected software versions of CVE-2026-20079 and CVE-2026-20316, and will release a comprehensive hardening release next week consisting of these hotfixes along with other internally discovered vulnerabilities.