Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Thousands of ebikes seized by London councils as anger rises over blocked paths | Cycle hire schemes

    September 12, 2026

    From black-clad agitators to an appeal for ‘Tommo’s Mum’: an unsettling week with the Patriot Platform | Immigration and asylum

    September 12, 2026

    We Tried the Most Popular Mushroom Coffees. These Are the Best (2026)

    September 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Thousands of ebikes seized by London councils as anger rises over blocked paths | Cycle hire schemes
    • From black-clad agitators to an appeal for ‘Tommo’s Mum’: an unsettling week with the Patriot Platform | Immigration and asylum
    • We Tried the Most Popular Mushroom Coffees. These Are the Best (2026)
    • Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
    • Blockstream Tells Hackers To Return Remaining Bitcoin Stolen In Liquid Theft
    • Review: Sally Hayden’s ‘This Is Also a Love Story’ Reimagines War Reporting
    • ‘War on terror’: How 9/11 changed the language of conflict | Human Rights News
    • Call it the Miliband doctrine. Let’s hope the new Israeli settlement boycott is just the start | Steve Bloomfield
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 12, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 11, 2026Vulnerability / Malware

    Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.

    The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

    The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.

    Cybersecurity

    Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat actors. These include –

    • UAT-12197, which has exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive (JAR)-based command executor to query internal databases and obtain user authentication data and credentials
    • UAT-11823, which has exploited both CVE-2026-20079 and CVE-2026-20316 to deliver a Netcat-based reverse shell, two bash scripts to harvest managed-device configurations, and a variant of Cyclops Blink, a modular ELF implant previously attributed to the Russian state-sponsored hacking group Sandworm
    • UAT-11988, a ransomware operation that has exploited CVE-2026-20316 for initial access and then used legitimate built-in FMC tooling as part of a living-off-the-land (LotL) attack to conduct extensive reconnaissance of the victim’s environment, drop tunneling tools to maintain network access, collect credentials, build a target list of endpoints to encrypt, terminate security tools, and deploy Qilin ransomware on selected systems.

    “Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316,” Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.

    The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, was added to the KEV catalog in late July 2026.

    Cisco Credentials Deploy Exploited flaws FMC Qilin ransomware Steal
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Passkey-themed phishing attacks lead to Microsoft 365 data theft

    PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    Your Critical Vulnerabilities Might Not Be Your Biggest Risk

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    GitLab Vulnerability Exploited One Day After Disclosure

    Why AI raises the stakes for exposure validation

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Thousands of ebikes seized by London councils as anger rises over blocked paths | Cycle hire schemes

    September 12, 2026

    From black-clad agitators to an appeal for ‘Tommo’s Mum’: an unsettling week with the Patriot Platform | Immigration and asylum

    September 12, 2026

    We Tried the Most Popular Mushroom Coffees. These Are the Best (2026)

    September 12, 2026

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    September 12, 2026
    Latest Posts

    After 3 reverse stock splits and a $13.5M loss, this real estate firm bet $8M on crypto it may not be allowed to withdraw

    August 3, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    Europe’s ETS revision is an opportunity to strengthen maritime competitiveness – POLITICO

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Thousands of ebikes seized by London councils as anger rises over blocked paths | Cycle hire schemes

    September 12, 2026

    From black-clad agitators to an appeal for ‘Tommo’s Mum’: an unsettling week with the Patriot Platform | Immigration and asylum

    September 12, 2026

    We Tried the Most Popular Mushroom Coffees. These Are the Best (2026)

    September 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.