Cisco has disclosed that threat actors are actively exploiting two high-severity vulnerabilities in its Secure Firewall Management Center (FMC) software, using the flaws to steal credentials and deploy Qilin ransomware. The company's advisory highlights campaigns targeting the central management platform for Cisco's firewall ecosystem.
The primary vulnerability under active exploitation is CVE-2026-20079, a critical authentication bypass flaw carrying a CVSS score of 10.0. The flaw exists in the FMC's web interface and allows an unauthenticated remote attacker to bypass authentication checks entirely. A second vulnerability, CVE-2026-20072, is also implicated in these attacks. Cisco's summary indicates that multiple threat clusters are leveraging these flaws in campaigns linked to both ransomware operations and state-sponsored activity.
The exploitation campaign underscores the immediate risk to organizations running Cisco FMC. As the central command and control point for firewall policies and monitoring, a compromised FMC grants attackers deep access to an organization's network defenses. From this position, adversaries can manipulate security configurations and gain broad visibility into network activity.
Security experts advise that applying the vendor-provided patches is the most critical first step. A layered defense strategy is also strongly recommended. Organizations should isolate the FMC management interface on a dedicated network segment with strict access controls. Enabling multi-factor authentication for all administrative access adds an important additional security layer.
Continuous monitoring is essential. Security teams should review FMC audit logs for unusual login attempts, unexpected configuration changes, or other signs of anomalous activity. Incident response plans should account for the possibility that a single initial compromise could lead to multiple attack outcomes, and teams should be prepared to investigate and respond accordingly.
The active weaponization of these vulnerabilities demonstrates that threat actors are quick to exploit flaws in critical security infrastructure. For Cisco FMC administrators, prompt patching and rigorous hardening of the management plane are now paramount to prevent compromise.
Cisco披露,威脅行為者正積極利用其Secure防火牆管理中心(FMC)軟件中的兩個高嚴重性漏洞,利用這些漏洞竊取憑證並投放Qilin勒索軟件。該公司的安全公告重點提及針對Cisco防火牆生態系統核心管理平台的攻擊行動。
目前正被積極利用的主要漏洞是CVE-2026-20079,這是一個CVSS評分達10.0滿分的關鍵驗證繞過漏洞。該漏洞存在於FMC的網絡介面,允許未經驗證的遠端攻擊者完全繞過驗證檢查。第二個漏洞CVE-2026-20072亦涉及這些攻擊。根據Cisco的摘要顯示,多個威脅組織正利用這些漏洞,發起涉及勒索軟件行動及國家支持活動的攻擊。
此次攻擊行動凸顯了運行Cisco FMC的機構面臨的即時風險。作為防火牆策略及監控的核心指揮控制點,被入侵的FMC將授予攻擊者深入訪問機構網絡防禦體系的權限。攻擊者可藉此篡改安全配置,並廣泛獲取網絡活動的可視化能力。
安全專家建議,應用供應商提供的修補程式是最關鍵的首要步驟。同時強烈建議採用縱深防禦策略。機構應將FMC管理介面隔離至配有嚴格存取控制的專用網絡段。為所有管理存取啟用多重身份驗證可增加重要的額外安全層。
持續監控至關重要。安全團隊應審查FMC審計日誌,留意異常登入嘗試、未預期的配置變更或其他異常活動跡象。事件應對計畫應考慮單一初始入侵可能導致多種攻擊結果的情況,團隊應做好相應調查及應對準備。
這些漏洞的活躍武器化表明,威脅行為者能迅速利用關鍵安全基礎設施中的漏洞。對Cisco FMC管理員而言,及時修補及嚴格加固管理平台現已成為防止入侵的首要任務。
