hacker-news · Crawled Jul 30, 2026

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

1 IoCs
Read original article ↗

AI Summary

A zero-day vulnerability, CVE-2026-20316, in Cisco Secure Firewall Management Center (FMC) Software is under active exploitation, allowing unauthenticated remote attackers to log in using static credentials for a low-privileged account and access sensitive data. The vulnerability stems from hardcoded credentials, and while its CVSS score is 5.3, Cisco classifies it as High risk due to potential privilege escalation when chained with other flaws. Indicators of compromise include the presence of '/var/tmp/license.tmp' in system logs. Cisco has released hotfixes for multiple affected versions and urges immediate patching, especially for FCEB agencies by August 1, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename /var/tmp/license.tmp Details →