logo

Cisco Secure FMC && hard-coded password exploited in Zero-Day attacks

ID: 35030942-272d-5388-b5af-e482e0438e30

STIX ID: report--35030942-272d-5388-b5af-e482e0438e30

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2026-07-30

Date Updated: 2026-07-31

...
...

A critical zero-day (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC) allows unauthenticated attackers to use static low-privileged credentials to log in to affected systems. Cisco has released hotfixes for multiple FMC releases and advises immediate patching, reviewing /var/log/messages for entries referencing /var/tmp/license.tmp, rotating credentials and certificates if compromised, and ensuring the FMC management interface is not exposed to the public internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.