Cisco firewall-management flaws are being linked to ransomware activity

The signal in one glance
What you need to know
- Threat groups are reportedly exploiting recently patched flaws in Cisco Secure Firewall Management Center, including a critical authentication-bypass issue identified as CVE-2026-20079.
- Management systems deserve priority because they can provide control over security infrastructure rather than merely one endpoint.
- Action: Inventory Secure Firewall Management Center instances, confirm affected versions, and apply the vendor’s fixes according to approved change procedures; do not assume a recent patch proves prior exploitation did not occur.
What happened
Threat groups are reportedly exploiting recently patched flaws in Cisco Secure Firewall Management Center, including a critical authentication-bypass issue identified as CVE-2026-20079. The supplied account says the activity has involved credential theft, elevated access, and deployment of Qilin ransomware.