Imagine you run IT for a mid-size biotech. Your firewall policy, the thing that decides what traffic reaches your lab systems and your research data, is managed from a single console. Now imagine an attacker doesn’t have to break through the firewall at all. They just log into the console that runs it, and from there they own the room.
That is the situation Cisco disclosed this month, and it is worth a close look if your organization runs Cisco Secure Firewall Management Center.
What Cisco actually found
According to The Hacker News reporting on the disclosure, Cisco revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center vulnerabilities.
The first flaw, CVE-2026-20079, carries a CVSS score of 10.0. The Hacker News describes it as an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. A 10.0 is the top of the scale. Unauthenticated means the attacker needs no credentials to start. Root access means they end up owning the box.
The second flaw, CVE-2026-20316, carries a CVSS score of 5.3. According to The Hacker News, it could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data, and it can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.
Cisco Talos identified three clusters of post-compromise activity, per The Hacker News. One cluster, tracked as UAT-12197, exploited CVE-2026-20079 to deploy web shells and a command executor to query internal databases and obtain user authentication data and credentials. A second cluster, UAT-11823, exploited both flaws and delivered a variant of Cyclops Blink, a modular implant The Hacker News reports was previously attributed to the Russian state-sponsored group Sandworm. The third cluster, UAT-11988, is described as a ransomware operation that exploited CVE-2026-20316 for initial access, then used legitimate built-in FMC tooling to conduct reconnaissance, collect credentials, terminate security tools, and deploy Qilin ransomware on selected systems.
That last detail matters. According to The Hacker News, that group used the firewall manager’s own built-in tooling to move through the environment, an approach the report describes as living off the land. The tool meant to protect the network became the tool used to map it.
Why this lands harder in life sciences
A compromised firewall manager is a bad day for any organization. In a biotech or medical device company, the stakes are shaped differently.
Your research IP is the asset. A credential-harvesting cluster like the one Cisco describes does not need to encrypt anything to hurt you. It quietly collects the keys to your systems, and years of protected research can walk out the door before anyone notices. The state-sponsored cluster in this disclosure is a reminder that some attackers are after data, not a ransom note.
Then there is the ransomware angle. If a Qilin deployment locks lab instruments, sample tracking, or the systems that hold study data, the disruption is not just operational. It touches data integrity, and data integrity is the foundation of FDA 21 CFR Part 11 and GxP expectations. An inspector asks how you know your records are complete and unaltered. “We had a ransomware event and rebuilt from backups” is a harder conversation than any of us want to have.
The uncomfortable part is that none of the three clusters here relied on a phishing email or a careless employee. They came in through an infrastructure appliance. That means your usual awareness training, however good, was never going to be the control that stopped this one.
What to do now
Cisco strongly advised customers to apply the hotfixes it has already released for CVE-2026-20079 and CVE-2026-20316, per The Hacker News, and said it intends to ship a broader hardening release. On top of that, The Hacker News reports that the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the patches by September 12, 2026. When CISA sets a federal deadline on a flaw, that is a signal to everyone that it is being used in the wild right now.
Here is where to start:
- Confirm whether you run Cisco Secure Firewall Management Center, and which version. If you outsource IT, this is a one-message question to your provider today.
- Apply the released hotfixes for both CVEs. Do not wait for the broader hardening release Cisco described. The exploitation is already happening.
- Restrict access to the FMC web interface. A management console reachable from the open internet is a door you can close.
- Assume credentials may have been touched if you were exposed. Rotate them, and review authentication logs for the kind of database queries and web shell activity Cisco described.
- Check that your backups for lab and study systems are recent, tested, and isolated from the network an attacker would traverse.
The honest takeaway is that the tools protecting your research are themselves attack surface. That is not a reason for alarm. It is a reason to treat your security infrastructure with the same patch discipline you already apply to your lab systems.
Common Questions
Are we affected if we don’t run Cisco FMC? These specific vulnerabilities are in Cisco Secure Firewall Management Center. If you do not run that product, these two CVEs do not apply to you directly. The broader lesson, that management consoles are high-value targets, applies to everyone.
How urgent is patching, really? Urgent. According to The Hacker News, CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog with a September 12, 2026 deadline for federal agencies, which means it is being actively exploited. CVE-2026-20316 was added to that catalog in late July 2026.
What is Qilin? In this disclosure it is the ransomware the third threat cluster deployed after gaining access, per The Hacker News. The concerning part for a research organization is not just the encryption, it is that the group collected credentials and mapped the environment first.
We use a managed IT provider. What should we ask them? Ask three things: do we run Cisco FMC, have the hotfixes for both CVEs been applied, and is our management interface reachable from the internet. A good provider will already know the answers.
centrexIT has been the IT team Life Sciences organizations across the West have trusted since 2002. If a disclosure like this leaves you unsure where your research data actually sits or how exposed your infrastructure is, that uncertainty is worth closing. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/assessment/cybersecurity/
Sources
- Cisco disclosed three threat clusters exploited two patched FMC flaws: The Hacker News, “Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware” (2026), https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html
- CVE-2026-20079 details and CVSS 10.0: The Hacker News, “Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware” (2026), https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html
- CISA KEV catalog addition and September 12, 2026 deadline: The Hacker News, “Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware” (2026), https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team