Bleepingcomputer Cisco FMC Static Credential Vulnerability Under Active Exploitation
Article Content
- •CVE-2026-20316 allows unauthenticated access to sensitive data via hardcoded credentials.
- •Cisco has released hotfixes for affected FMC software versions; immediate patching is advised.
- •CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
Cisco has reported a high-severity vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC) software, which is being actively exploited in the wild. The flaw arises from hardcoded static credentials for a low-privileged account, allowing unauthenticated remote attackers to log in and access sensitive data. Despite a CVSS score of 5.3, Cisco has assigned a High severity rating due to the potential for privilege escalation when combined with other vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog. Cisco has released hotfixes for several affected software versions, urging immediate installation. The vulnerability affects all configurations of Cisco Secure FMC Software but does not impact Cloud-Delivered FMC or other firewall software. Administrators are advised to check logs for indicators of compromise and to contact Cisco's Technical Assistance Center for recovery assistance. The vulnerability was first disclosed on July 29, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (27)
Following this threat?
Track AtlasRAT, Cisco and CVE-2026-20079 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…