Cisco FMC static credential vulnerability exploited as a zero-day
5 hours ago
- Cisco Secure Firewall Management Center (FMC) has a static credential vulnerability (CVE-2026-XXXX) with a CVSS score of 5.3 (Medium) but rated High by Cisco due to potential privilege escalation.
- The vulnerability allows an unauthenticated, remote attacker to log in with a low-privileged account and access sensitive data.
- Cisco has released hotfixes for affected FMC versions (7.0, 7.2, 7.4, 7.6, 7.7, 10.0); no workarounds exist, and active exploitation has been reported since July 2026.
- Exploitation can be detected using the CLI command `cat /var/log/messages | grep license` for specific log entries.
- Cisco recommends rotating all credentials, keys, and certificates if exploitation is suspected, and upgrading to fixed software immediately.