Cyber Threat Pulse

Cisco FMC vulnerabilities exploited for firewall takeover and ransomware

Cisco FMC vulnerabilities exploited for firewall takeover and ransomware

CVE-2026-20079 and CVE-2026-20316 are reportedly being exploited against Cisco Firepower Management Center by nation-state and ransomware actors, including Sandworm-linked activity and Qilin deployment. Organizations should validate hotfixes and hunt for unauthenticated root access, reverse shells, web shells, configuration theft, credential compromise, and persistence on firewall-management infrastructure.

Sources (2)
Updated Sep 13, 2026
Cisco FMC vulnerabilities exploited for firewall takeover and ransomware - Cyber Threat Pulse | NBot | nbot.ai