Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

2026-09-11T14:51:40Z2a5941e92d204c09e6c61afc223222deae9ab675ffc20697fc1fcf370c8264ed
CVE-2026-20079CVE-2026-75650CVE-2026-87491Active Directory theftCISA KEVCisco Secure Firewall Management CenterF5 BIG-IP APMGoogle ChromePoisonedRefreshQilin ransomwareSonicWallactive exploitationbrowser exploitationcredential theftenterprise appliancesfileless rootkitnation-state activityroot accesszero-day

What happened

Security Affairs reports widespread exploitation of critical enterprise and browser vulnerabilities, including Cisco Secure Firewall Management Center authentication bypass CVE-2026-20079, SonicWall flaws, actively exploited Chrome V8 zero-day CVE-2026-87491, F5 BIG-IP APM compromise involving the PoisonedRefresh fileless rootkit, and additional vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog. Campaigns include credential theft, root access, Active Directory compromise, ransomware deployment, nation-state espionage, and memory-resident web-shell injection.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2a5941e92d204c09e6c61afc223222deae9ab675ffc20697fc1fcf370c8264ed
Enrichment time
2026-09-11T14:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware · Baitaphish