Security · 3 MIN READ

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco says attackers are actively exploiting two recently patched Secure Firewall Management Center vulnerabilities in campaigns involving credential theft, Qilin ransomware, and state-sponsored activity. Accurate asset inventory, software tracking, and structured remediation workflows are critical to identifying exposed systems and reducing risk.

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has disclosed active exploitation of two recently patched vulnerabilities in Secure Firewall Management Center software. Three distinct threat clusters linked to ransomware and state-sponsored attacks have reportedly used the flaws to steal credentials and deploy Qilin ransomware, turning an exposed management platform into a high-priority security risk.


What Cisco Disclosed

One of the flaws, CVE-2026-20079, is a critical authentication bypass vulnerability in the Secure Firewall Management Center web interface. It could allow an unauthenticated remote attacker to bypass authentication, and Cisco reports that attackers are already exploiting the two patched vulnerabilities in real-world campaigns.

The disclosed activity illustrates how multiple threat groups can target the same management technology for different objectives, including credential theft, ransomware deployment, and state-sponsored operations.


Why Management Systems Require Fast Action

Firewall management systems occupy a sensitive position because they help administrators control security infrastructure. When a vulnerability affects that management layer, defenders need to determine quickly which systems are deployed, which software versions they run, and whether remediation has been completed.

Key response priorities include:

  • Identify every deployed Secure Firewall Management Center instance.

  • Verify software and firmware versions against Cisco's current security guidance.

  • Apply the relevant vendor patches and mitigations.

  • Review access activity and investigate possible credential exposure.

  • Rotate affected credentials through an approved process.

  • Preserve configuration history before and after remediation.

  • Confirm that internet-facing management access is appropriately restricted.


From Vulnerability Alert to Verified Remediation

A vulnerability notice is only the beginning of the response. Organizations also need a reliable way to associate the affected technology with real assets, assign remediation work, track changes, and verify that no overlooked system remains exposed.

This is especially important in multi-vendor environments, where device records, software information, configuration backups, and security findings may otherwise be scattered across separate tools and spreadsheets.


How ConnectMyAssets Helps

ConnectMyAssets provides an on-prem platform for managing the operational data needed during incidents like this, with all data remaining inside the organization's environment.

  • Dynamic CMDB automatically discovers supported Cisco infrastructure and maintains an inventory that teams can use to locate potentially affected assets.

  • CVE Tracking associates vulnerability information with individual assets, helping teams prioritize devices that require investigation or remediation.

  • End-of-Life / End-of-Support tracking highlights systems that may no longer have a viable vendor-supported update path.

  • Backup & History records configuration versions with SHA256 verification, giving teams a traceable before-and-after record and one-click rollback for configuration changes.

  • Automation & ZTP supports controlled deployment of approved configuration changes across managed infrastructure.

  • Credential Vault centralizes credentials used for network administration, while SSH Bastion provides audited browser-based administrative access.

  • Compliance Engine measures the environment against frameworks including NIS2, ISO 27001, PCI-DSS, CISA, NIST, and HIPAA, helping connect remediation activity with broader control requirements.

These capabilities do not replace Cisco's patches or incident-response guidance. They help network and security teams establish exposure, coordinate remediation, preserve evidence of change, and verify that affected managed assets have been addressed.

Source: The Hacker News

Share this articleLinkedIn ↗Email ↗

Keep exploring.

All articles
Security

Critical Check Point Management Flaw Allows Root Code Execution

A critical vulnerability in Check Point Security Management and Log Servers could let an unauthenticated network attacker execute code as root. Because the management server controls firewall policy and administrator access, organizations should apply the LivePatch fix and verify every potentially exposed system.

Read article
Security

Check Point Management-Server RCE: What to Track

CERT-FR has reported a vulnerability in Check Point products that can allow remote arbitrary code execution. Administrators should identify affected management assets, apply the required vendor updates, and search SmartConsole logs for the login-failure pattern highlighted in the advisory.

Read article
Security

Cisco ISE Zero-Day Under Active Attack

Cisco has disclosed a maximum-severity authentication-bypass vulnerability in ISE that is already being exploited. Network teams should identify affected systems, follow Cisco’s remediation guidance, and document patch or mitigation status across their network-access infrastructure.

Read article