Cisco FMC Auth Bypass Flaw Actively Exploited in Ransomware Attacks
Threat actors are exploiting a critical Cisco FMC vulnerability to steal credentials and deploy Qilin ransomware. CISA has mandated federal agencies to patch by September 12.
TL;DR
- CVE-2026-20079 is a critical auth bypass flaw in Cisco FMC (CVSS 10.0).
- Exploited by ransomware groups and state-sponsored attackers.
- CISA added it to KEV catalog with a Sept 12 patch deadline for federal agencies.
- Attackers use the flaw to gain unauthorized access and deploy Qilin ransomware.
- Organizations using Cisco FMC should prioritize immediate patching.
A critical authentication bypass vulnerability in Cisco’s Secure Firewall Management Center (FMC), tracked as CVE-2026-20079, is being actively exploited by multiple threat actors. These include both financially motivated ransomware groups and suspected state-sponsored attackers. The flaw allows unauthenticated remote attackers to bypass security controls, potentially leading to credential theft and system compromise.
In response to growing exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to apply patches by September 12, 2026. Organizations managing network infrastructure through Cisco FMC are strongly advised to assess their exposure and remediate immediately.
Vulnerability Details
- CVE-2026-20079 affects the web interface of Cisco Secure Firewall Management Center (FMC).
- It is an authentication bypass vulnerability with a CVSS score of 10.0 (critical).
- An unauthenticated, remote attacker can exploit it to gain administrative access.
- No user interaction or prior authentication is required for exploitation.
- Patched by Cisco in recent software updates; organizations should upgrade immediately.
Observed Threat Activity
- At least three distinct threat clusters are exploiting CVE-2026-20079.
- One attack vector involves credential theft followed by deployment of Qilin ransomware.
- State-sponsored threat actors are also believed to be leveraging the flaw.
- CISA confirmed active exploitation and added the flaw to its KEV list.
- Federal agencies must patch by September 12, 2026 to comply with binding directives.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.