The Bottom Line: A static credential vulnerability in Cisco FMC (CVE-2026-20316) is being actively exploited in attacks to gain unauthorized access to firewalls.
Cisco warns of a critical security flaw in the Secure Firewall Management Center (FMC) that allows attackers to gain access to affected systems using immutable default credentials. The vulnerability is already being exploited in zero-day attacks.
Cisco has cautioned organizations: The Secure Firewall Management Center (FMC) contains a high-severity vulnerability (CVE-2026-20316) affecting static, immutable credentials. These enable attackers to log directly into vulnerable systems without needing to crack a password.
What is distinctive about this threat is its active use in zero-day attacks. This means that attackers are already exploiting the flaw before patches are available, allowing them to gain unauthorized access to critical firewall management infrastructure. FMC is centrally deployed in many enterprise environments to manage and monitor firewall policies.
For CISOs, the immediate priority is to identify affected FMC installations and implement available security measures. Static credentials are considered a classic but particularly critical vector for lateral movement and persistent access to network infrastructure. Exploitation in zero-day campaigns indicates targeted, well-informed attack behavior.
Source: www.bleepingcomputer.com · Published 29 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.