Skip to main content
Security

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco warns of FMC static credential flaw exploited in zero-day attacks Image: Primary
Cisco warned Tuesday that a high-severity static credential vulnerability in its Secure Firewall Management Center software was actively exploited in zero-day attacks. The company said the flaw, tracked as CVE-2026-20316, allows an unauthenticated remote attacker to use built-in low-privilege credentials to log in and access sensitive data. Cisco assigned a High severity rating despite a CVSS score of 5.3 because the access can be combined with other vulnerabilities to elevate privileges, though it has not identified those additional flaws. The vulnerability affects Secure FMC Software releases 7.0 through 10.0 regardless of configuration but does not impact Cloud-Delivered FMC or several other Cisco products. Cisco released hot fixes for all affected versions and said there are no workarounds. The company said it became aware of active exploitation in July 2026 but has not disclosed when attacks began, who is responsible, or which organizations were targeted. Jimi Sebree of Horizon3.ai reported the vulnerability. Cisco also updated an advisory for a separate critical authentication bypass flaw, CVE-2026-20079, which carries a maximum CVSS score of 10.0. Cisco said it is not aware of malicious exploitation of that vulnerability. Both advisories share an indicator of compromise involving a log entry for /var/tmp/license.tmp, though Cisco has not explained whether the flaws are connected.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security AI
Security AI

Vendor study finds AI-related SOC alerts up 685% but almost all noise

A security vendor's review of roughly 16.9 million enterprise SOC alerts found about 73,000, or 0.43%, were tied to AI tools and agents, with that volume up 685% between February and June 2026. The vendor sorted the AI-related al...

Security
Security

Dutch NCSC warns Check Point VPN flaws face imminent exploitation

The Dutch National Cyber Security Centre warned that exploitation of two critical Check Point VPN flaws is imminent and urged organizations to install available updates. CVE-2026-85102 involves improper certificate-data validation...