The ransomware crew skipped Cisco's 10.0. It logged in with the 5.3 that CISA listed back in July
CISA gave agencies until 12 September to deal with exploited flaws in Cisco's firewall manager, Citrix NetScaler and FortiOS. Talos's research shows the Qilin-linked cluster ignored the CVSS 10.0 bypass and used a hard-coded password flaw CISA had listed in July — and the federal instruction for all of it starts with evidence, not the patch.