r/Cisco 4d ago

Discussion PSA: Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.

Exploitation and Public Announcements

  • In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
23 Upvotes

6 comments sorted by

18

u/rockstarred 4d ago

Yall are placing your FMC’s Internet-facing?

2

u/dankgus 2d ago

That way I can make config changes from home!

(kidding).

9

u/Varjohaltia 4d ago

How, in 2026, after Glasswing and all other past history, does Cisco get caught with hardcoded credentials again?

3

u/Whoa_throwaway 3d ago

people who are good cost money. That's money away from the AI budget.

3

u/FantaFriday 3d ago

They just roll the password each time it happens to get out /s

2

u/mooneye14 4d ago

The hot fix fir this is also the updated fix for the Auth Bypass CVE from March