Hasty Briefsbeta

Bilingual

Cisco FMC static credential vulnerability exploited as a zero-day

5 hours ago
  • Cisco Secure Firewall Management Center (FMC) has a static credential vulnerability (CVE-2026-XXXX) with a CVSS score of 5.3 (Medium) but rated High by Cisco due to potential privilege escalation.
  • The vulnerability allows an unauthenticated, remote attacker to log in with a low-privileged account and access sensitive data.
  • Cisco has released hotfixes for affected FMC versions (7.0, 7.2, 7.4, 7.6, 7.7, 10.0); no workarounds exist, and active exploitation has been reported since July 2026.
  • Exploitation can be detected using the CLI command `cat /var/log/messages | grep license` for specific log entries.
  • Cisco recommends rotating all credentials, keys, and certificates if exploitation is suspected, and upgrading to fixed software immediately.