live markets
S&P 5007,600.50▲ 1.48%NASDAQ25,913.90▲ 2.13%DOW53,178.41▲ 1.32%GOLD4,112.90▲ 0.55%WTI CRUDE80.17▼ 0.21%BRENT83.96▲ 0.23%EUR/USD1.1521▲ 0.06%GBP/USD1.3447▲ 0.15%USD/JPY157.71▲ 0.33%NAT GAS2.737▼ 1.58%
pulseofnations.
Tue, Aug 4 2026 — 11:31 UTC telegram ↗ Join the wire

Cisco Warns Firewall Zero-Day Is Under Active Attack, Urges Patch Now

Cisco patched a high-severity zero-day in its Secure Firewall Management Center that lets attackers use hard-coded credentials to access sensitive network data.

Cisco has released emergency security updates for CVE-2026-20316, a high-severity zero-day vulnerability in its Secure Firewall Management Center software that is being actively exploited in the wild. The flaw stems from static credentials embedded in the FMC web interface, allowing unauthenticated remote attackers to gain access to affected devices.

The Cybersecurity and Infrastructure Security Agency confirmed active exploitation and added the vulnerability to its Known Exploited Vulnerabilities catalog, directing federal agencies and critical infrastructure operators to apply patches immediately. CISA warned that the flaw could expose sensitive configuration data, firewall rules, and network credentials stored on affected management servers.

Cisco urged all customers running affected FMC versions to rotate all user credentials, API keys, and certificates on impacted devices, noting that the embedded static credentials may have been compromised even before patches were available. The company said it became aware of the issue after detecting unauthorized access attempts against customer environments.

The vulnerability affects Cisco Secure FMC, a centralized management platform used to configure and monitor multiple Cisco Secure Firewall devices across enterprise networks. An attacker exploiting CVE-2026-20316 could potentially gain full administrative control over the management plane, including the ability to modify firewall policies and exfiltrate stored credentials.

Security researchers at multiple firms, including SOC Prime and Help Net Security, published analysis confirming that the static credentials are extractable from the FMC software, making exploitation straightforward for any attacker with network access to the management interface. The flaw does not require authentication or user interaction to exploit.

The incident underscores the ongoing risk of hardcoded credentials in enterprise network equipment, a class of vulnerability that has plagued vendors from Cisco to Juniper in recent years. Organizations are advised to ensure FMC management interfaces are not exposed to untrusted networks and to apply the available patches as soon as possible.

Sources: SecurityWeek, BleepingComputer, The Hacker News

React to this dispatch
Share this dispatch Telegram X WhatsApp

discussion

Join the discussion

Your email address will not be published. Required fields are marked *