Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco says attackers are actively exploiting two recently patched Secure Firewall Management Center vulnerabilities in campaigns involving credential theft, Qilin ransomware, and state-sponsored activity. Accurate asset inventory, software tracking, and structured remediation workflows are critical to identifying exposed systems and reducing risk.

Cisco has disclosed active exploitation of two recently patched vulnerabilities in Secure Firewall Management Center software. Three distinct threat clusters linked to ransomware and state-sponsored attacks have reportedly used the flaws to steal credentials and deploy Qilin ransomware, turning an exposed management platform into a high-priority security risk.
What Cisco Disclosed
One of the flaws, CVE-2026-20079, is a critical authentication bypass vulnerability in the Secure Firewall Management Center web interface. It could allow an unauthenticated remote attacker to bypass authentication, and Cisco reports that attackers are already exploiting the two patched vulnerabilities in real-world campaigns.
The disclosed activity illustrates how multiple threat groups can target the same management technology for different objectives, including credential theft, ransomware deployment, and state-sponsored operations.
Why Management Systems Require Fast Action
Firewall management systems occupy a sensitive position because they help administrators control security infrastructure. When a vulnerability affects that management layer, defenders need to determine quickly which systems are deployed, which software versions they run, and whether remediation has been completed.
Key response priorities include:
- Identify every deployed Secure Firewall Management Center instance.
- Verify software and firmware versions against Cisco's current security guidance.
- Apply the relevant vendor patches and mitigations.
- Review access activity and investigate possible credential exposure.
- Rotate affected credentials through an approved process.
- Preserve configuration history before and after remediation.
- Confirm that internet-facing management access is appropriately restricted.
From Vulnerability Alert to Verified Remediation
A vulnerability notice is only the beginning of the response. Organizations also need a reliable way to associate the affected technology with real assets, assign remediation work, track changes, and verify that no overlooked system remains exposed.
This is especially important in multi-vendor environments, where device records, software information, configuration backups, and security findings may otherwise be scattered across separate tools and spreadsheets.
How ConnectMyAssets Helps
ConnectMyAssets provides an on-prem platform for managing the operational data needed during incidents like this, with all data remaining inside the organization's environment.
- Dynamic CMDB automatically discovers supported Cisco infrastructure and maintains an inventory that teams can use to locate potentially affected assets.
- CVE Tracking associates vulnerability information with individual assets, helping teams prioritize devices that require investigation or remediation.
- End-of-Life / End-of-Support tracking highlights systems that may no longer have a viable vendor-supported update path.
- Backup & History records configuration versions with SHA256 verification, giving teams a traceable before-and-after record and one-click rollback for configuration changes.
- Automation & ZTP supports controlled deployment of approved configuration changes across managed infrastructure.
- Credential Vault centralizes credentials used for network administration, while SSH Bastion provides audited browser-based administrative access.
- Compliance Engine measures the environment against frameworks including NIS2, ISO 27001, PCI-DSS, CISA, NIST, and HIPAA, helping connect remediation activity with broader control requirements.
These capabilities do not replace Cisco's patches or incident-response guidance. They help network and security teams establish exposure, coordinate remediation, preserve evidence of change, and verify that affected managed assets have been addressed.
Source: The Hacker News



