Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that CVE-2026-20316, a high-severity Secure Firewall Management Center static credential flaw, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. Cisco also patched CVE-2026-20079, a critical FMC authentication bypass issue that can let unauthenticated attackers run commands as root, and released hot fixes for affected Secure FMC versions. #Cisco #CVE-2026-20316 #CVE-2026-20079 #SecureFirewallManagementCenter #Horizon3ai

Keypoints

  • CVE-2026-20316 uses static credentials built into Cisco Secure FMC Software.
  • An unauthenticated attacker can log in remotely and access sensitive data.
  • Cisco confirmed active exploitation and has no workaround beyond hot fixes.
  • Affected versions include Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.
  • Cisco also patched CVE-2026-20079, a critical authentication bypass flaw.

Read More: https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/