Act
active
Cisco FMC Auth Bypass CVE-2026-20079 Exploited for Qilin Ransomware
- Engineer — Act: CVE-2026-20079 is CVSS 10.0, CISA KEV-listed, EPSS 0.76, with a public GitHub PoC and confirmed active exploitation; patch Cisco FMC to the vendor-released fixed version immediately, and if the management interface was internet-accessible, treat the device as compromised and rotate all credentials it manages.
- SOC/IR — Act: Multiple threat clusters including Qilin ransomware operators are actively exploiting this; hunt for unauthenticated access patterns against FMC web interfaces since the patch release date, sweep EDR telemetry on adjacent hosts for Qilin staging behavior, and request FMC access logs from the network team for anomaly review.
- Leader — Act: Cisco FMC is core security infrastructure at many enterprises; confirm with your engineering team whether FMC is deployed and patched, and prepare a brief for leadership given active ransomware deployment and state-sponsored actor involvement — the combination of CVSS 10.0 and Qilin activity raises material-incident exposure if your environment is unpatched.
- Signals: CVE-2026-20079 — CISA KEV: listed, EPSS 0.76, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.