CuraSec

tag: Cisco-Fmc · 2 items

2026-09-11 · BleepingComputer · source ↗ #cisco-fmc#ransomware#state-sponsored
  • Engineer — Act: Two patched Cisco FMC vulnerabilities are confirmed exploited in the wild by multiple threat clusters. Patch Cisco Secure Firewall Management Center to the latest fixed version immediately and audit FMC access logs for signs of unauthorized activity.
  • SOC/IR — Act: Active exploitation by ransomware and state-sponsored actors across three clusters means assume-breach posture for any org running Cisco FMC. Hunt for unauthorized FMC access and policy changes since the vulnerability window; pull TTPs from the Cisco Talos advisory and map to ATT&CK for detection coverage.
  • Leader — Act: Exploitation by both ransomware and state-sponsored actors across three clusters elevates this beyond routine CVE noise. Confirm whether your organization runs Cisco FMC, verify your team has patched, and brief leadership if FMC is part of your network security architecture.
  • Engineer — Act: CVE-2026-20079 is CVSS 10.0, CISA KEV-listed, EPSS 0.76, with a public GitHub PoC and confirmed active exploitation; patch Cisco FMC to the vendor-released fixed version immediately, and if the management interface was internet-accessible, treat the device as compromised and rotate all credentials it manages.
  • SOC/IR — Act: Multiple threat clusters including Qilin ransomware operators are actively exploiting this; hunt for unauthenticated access patterns against FMC web interfaces since the patch release date, sweep EDR telemetry on adjacent hosts for Qilin staging behavior, and request FMC access logs from the network team for anomaly review.
  • Leader — Act: Cisco FMC is core security infrastructure at many enterprises; confirm with your engineering team whether FMC is deployed and patched, and prepare a brief for leadership given active ransomware deployment and state-sponsored actor involvement — the combination of CVSS 10.0 and Qilin activity raises material-incident exposure if your environment is unpatched.
  • Signals: CVE-2026-20079 — CISA KEV: listed, EPSS 0.76, public PoC on GitHub