Cisco Firewall Bugs Under Active Attack: Qilin Ransomware and State-Backed Hackers Exploiting Two Flaws
Cisco has disclosed that three separate threat groups, including ransomware crews and state-sponsored actors, are exploiting two vulnerabilities in its Secure Firewall Management Center (FMC) software. The more severe flaw, CVE-2026-20079, carries a maximum severity score and allows an unauthenticated attacker to bypass login protections entirely and gain root access to the device. The second flaw, CVE-2026-20316, lets an attacker log in with a low-privilege account to view sensitive data, and can be combined with other issues to escalate privileges further.
Cisco's Talos threat intelligence team said it has identified three distinct clusters of post-compromise activity on affected FMC systems, tied to both financially motivated ransomware operators and nation-state linked groups. Cisco has released hotfixes for both vulnerabilities and says it plans to ship a broader hardening update next week to address additional internally discovered issues.
The U.S. Cybersecurity and Infrastructure Security Agency has added both flaws to its Known Exploited Vulnerabilities catalog, with CVE-2026-20079 requiring federal agencies to patch by 12 September 2026. Given that these are network security devices sitting at the edge of corporate infrastructure, any delay in patching significantly widens the window for attackers to gain a foothold.