Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
2026-09-11T14:51:40Z•2a5941e92d204c09e6c61afc223222deae9ab675ffc20697fc1fcf370c8264ed
CVE-2026-20079CVE-2026-75650CVE-2026-87491Active Directory theftCISA KEVCisco Secure Firewall Management CenterF5 BIG-IP APMGoogle ChromePoisonedRefreshQilin ransomwareSonicWallactive exploitationbrowser exploitationcredential theftenterprise appliancesfileless rootkitnation-state activityroot accesszero-day
What happened
Security Affairs reports widespread exploitation of critical enterprise and browser vulnerabilities, including Cisco Secure Firewall Management Center authentication bypass CVE-2026-20079, SonicWall flaws, actively exploited Chrome V8 zero-day CVE-2026-87491, F5 BIG-IP APM compromise involving the PoisonedRefresh fileless rootkit, and additional vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog. Campaigns include credential theft, root access, Active Directory compromise, ransomware deployment, nation-state espionage, and memory-resident web-shell injection.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2a5941e92d204c09e6c61afc223222deae9ab675ffc20697fc1fcf370c8264ed
- Enrichment time
- 2026-09-11T14:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.