Cisco FMC vulnerabilities exploited for firewall takeover and ransomware
CVE-2026-20079 and CVE-2026-20316 are reportedly being exploited against Cisco Firepower Management Center by nation-state and ransomware actors, including Sandworm-linked activity and Qilin deployment. Organizations should validate hotfixes and hunt for unauthenticated root access, reverse shells, web shells, configuration theft, credential compromise, and persistence on firewall-management infrastructure.
Sources (2)
Updated Sep 13, 2026