What We Know
Cisco says attackers are exploiting two known vulnerabilities in its Secure Firewall Management Center, or FMC, and the flaws have been linked to both state-sponsored activity and ransomware operations.4Backed by 4 sourcescybernews.comhitechub.comhelpnetsecurity.comncijnetwork.com Cisco Talos identified three separate threat clusters associated with the exploitation, including actors connected to ransomware and state-sponsored attacks.1Backed by 1 sourceshitechub.com
Reported activity includes dropping web shells, stealing credentials, and deploying Qilin ransomware against targeted environments.2Backed by 2 sourcescybernews.comThe Hacker News The vulnerabilities are identified as CVE-2026-20079 and CVE-2026-20316, and reporting describes them as recently patched flaws.2Backed by 2 sourceshelpnetsecurity.comncijnetwork.com CISA has urged organizations to apply the available patches because the vulnerabilities are being exploited in ongoing attacks.1Backed by 1 sourcescybernews.com
Source Comparison
Aligned reportingCorroborates
- cybernews.com↗Reports exploitation of two Cisco FMC flaws, including web-shell activity, ransomware-linked operations and CISA’s urgent patching warning.
- hitechub.com↗Supports the account that Cisco Talos linked exploitation of two FMC flaws to three threat clusters involving ransomware and state-sponsored activity.
- The Hacker News↗Corroborates reporting that exploitation involved credential theft and deployment of Qilin ransomware against affected environments.
- helpnetsecurity.com↗Identifies the exploited FMC bugs as CVE-2026-20079 and CVE-2026-20316 and links them to nation-state and ransomware actors.
- ncijnetwork.com↗Reports that Cisco Talos attributed exploitation to ransomware and state-sponsored hackers and describes the flaws as recently patched.