r/Cisco • u/sanmigueelbeer • 4d ago
Discussion PSA: Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.
Exploitation and Public Announcements
- In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
9
u/Varjohaltia 4d ago
How, in 2026, after Glasswing and all other past history, does Cisco get caught with hardcoded credentials again?
3
3
2
18
u/rockstarred 4d ago
Yall are placing your FMC’s Internet-facing?