Back to advisories

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Two critical authentication bypass vulnerabilities in Cisco Secure Firewall Management Center (FMC) are being actively exploited by ransomware gangs and state-sponsored actors to deploy Qilin ransomware and Cyclops Blink malware. Any organization running FMC is a direct target. Successful exploitation grants unauthenticated remote code execution with full system compromise.

CRITICALAdvisorySep 12, 2026
Action required
Immediately patch Cisco FMC to the latest version addressing CVE-2026-20079 and CVE-2026-20316. In parallel, hunt for exploitation indicators: review FMC access logs for unauthenticated authentication bypass attempts, check for Qilin and Cyclops Blink IOCs on your network, and monitor for lateral movement from compromised FMC instances.
Affected products
Secure Firewall Management Center (FMC)Cisco