Independent cybersecurity news and intelligence
SourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
RansomwareCyberDeltaForce Newsroom

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

A security weakness in the affected technology is being tracked as CVE-2026-20079. The flaw is described as a authentication weakness vulnerability. An authentication weakness can let an attacker cross a security boundary without passing the identity checks that normally protect the affected function or service. The available…

The Hacker NewsSep 11, 2026, 6:19 AM UTC3 min readCVE-2026-20079
IN 30 SECONDS

What you need to know

What happenedSource reporting

A security weakness in the affected technology is being tracked as CVE-2026-20079. The flaw is described as a authentication weakness vulnerability. An authentication weakness can let an attacker cross a security boundary without passing…

Who is affectedSource reporting

Exposure — Required condition: an affected CVE-2026-20079 instance is reachable from a network position available to the attacker.

Exploitation statusCDF assessment

No active exploitation was identified in the current reporting reviewed.

Why it mattersSource reporting

0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass.

What to do nowCDF guidance

Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.

THE NEWS

What happened

Verified reporting in clear, practical language.

The attacks leverage CVE-2026-20079 (CVSS score: 10. Exposure — Required condition: an affected CVE-2026-20079 instance is reachable from a network position available to the attacker.

Defender interruption point — Identify remotely reachable CVE-2026-20079; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. Ransomware cases usually matter beyond encryption because the same access can support privilege escalation, lateral movement, data theft or disruption before the final extortion stage.

REFERENCES

Reference sources

CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

TECHNICAL PATH

Attack & Exploitation Path

How the attack can begin, what it may do, and where defenders can interrupt it.

  1. 1

    Exposure — Required condition: an affected CVE-2026-20079 instance is reachable from a network position available to the attacker.

  2. 2

    Confirmed Security outcome — successful exploitation can bypass the authentication boundary described in the reporting and reach functionality that should require trusted access.

  3. 3

    Defender interruption point — Identify remotely reachable CVE-2026-20079; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity.

DEFENDER ACTIONS

What security teams should do now

  • Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
  • Apply the vendor patch or mitigation for CVE-2026-20079 and validate the affected path after remediation.
  • Search Kubernetes and API audit logs for unexpected impersonation headers, group values, privilege use, or anomalous proxy requests.
OPEN QUESTIONS

What is not yet confirmed

  • Who was responsible has not yet been confirmed publicly.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards