Cisco warns ransomware groups are weaponizing newly‑patched FMC flaws to hijack firewalls and spread Qilin ransomware
Cisco disclosed that cyber‑criminals and state‑aligned actors have begun exploiting two recently patched vulnerabilities in its Secure Firewall Management Center (FMC) to pilfer administrator credentials and install the Qilin ransomware family.
The first flaw, identified as CVE‑2026‑20079, carries a maximum CVSS rating of 10.0 and permits an unauthenticated attacker to bypass the FMC's login mechanisms. A second, concurrently patched weakness allowed remote code execution on the management appliance, giving threat actors the ability to run arbitrary commands once inside the network.
Security researchers have traced activity to three separate threat clusters that combine traditional ransomware operators with groups linked to nation‑state sponsorship. These clusters appear to have coordinated their campaigns, leveraging the FMC bugs to gain privileged access before moving laterally across victim environments.
Once the attackers obtained valid FMC credentials, they used the management console to deploy Qilin ransomware payloads. The malware encrypts files on compromised hosts and displays a ransom note demanding payment, a pattern observed in several incidents reported over the past month.
Cisco’s advisory urges organizations to apply the latest FMC patches immediately, rotate all administrative passwords, and enable multi‑factor authentication where possible. The company also recommends reviewing firewall logs for anomalous login attempts and isolating management interfaces from general network traffic.
The episode underscores a growing trend: ransomware groups are increasingly targeting the control plane of enterprise security infrastructure. By compromising tools such as firewalls, attackers can bypass traditional defenses and achieve deeper footholds.
Analysts expect further exploitation attempts as the vulnerabilities remain fresh in the threat community’s toolbox. Cisco has pledged to monitor the situation closely and will issue additional guidance if new tactics emerge.
Comments (0)
Be the first to comment.
Join the discussion