Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

A Critical Vulnerability in Cisco’s FMC Software Exposes Organizations to Ransomware Attacks

A severe flaw in Cisco’s Firepower Management Center (FMC) software has been exploited by attackers to steal sensitive credentials and deploy the Qilin ransomware, putting thousands of organizations at risk. The vulnerability, which was disclosed in July 2023, allows hackers to gain unauthorized access to FMC systems and escalate privileges across domains.

The exploit works by targeting a weakness in the way FMC handles API requests, allowing attackers to bypass authentication mechanisms and inject malicious code into the system. Once inside, they can move laterally within the network, using stolen credentials to access sensitive areas and deploy malware such as Qilin ransomware. This potent combination of credential theft and privilege escalation makes it a lucrative opportunity for attackers looking to breach even the most secure networks.

The scope of this vulnerability is staggering, with an estimated 50,000 organizations worldwide potentially affected by the FMC flaw. Cisco has released patches to address the issue, but many organizations have yet to apply them, leaving their systems vulnerable to attack. The company’s own estimates suggest that a significant number of customers may not be aware they are running outdated software or may have failed to implement security best practices.

The Qilin ransomware, which is linked to this exploit, demands payment in Bitcoin and threatens to delete files if the ransom is not paid within 72 hours. While some victims have reported receiving decryption keys after paying the ransom, others have had their data destroyed, making it clear that this malware is a serious threat. The fact that Qilin can be deployed using stolen credentials makes it an even more insidious threat, as attackers can now bypass traditional security controls.

The good news is that Cisco’s patches are available and should be applied immediately to prevent exploitation of the FMC flaw. Additionally, organizations should implement robust security measures such as multi-factor authentication and regular backups to mitigate the impact of a potential ransomware attack. By taking proactive steps to address this vulnerability, organizations can protect themselves against the growing threat of credential-based attacks.

In light of these findings, it is essential for IT teams to review their network architectures and identify areas where privilege escalation could occur. Regularly updating software and implementing robust security controls will help prevent attackers from exploiting vulnerabilities like those in Cisco’s FMC software.


Source: The Hacker News — 2026-09-11