Cisco FMC static credential vulnerability exploited as a zero-day
nyku
11 points
3 comments
July 30, 2026
Related Discussions
Found 5 related stories in 36.2ms across 3,260 title embeddings via pgvector HNSW
- CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV slvnx · 31 pts · July 16, 2026 · 56% similar
- 24,650 internet-accessible BMCs leak password-derived hashes before login ilreb · 20 pts · July 28, 2026 · 54% similar
- Terabytes of credentials leaked in supply-chain attack RattlesnakeJake · 42 pts · August 13, 2026 · 52% similar
- Unauthenticated RCE in Motorola's MR2600 Router MrBruh · 78 pts · July 12, 2026 · 51% similar
- Build your own vulnerability harness ianrahman · 32 pts · July 10, 2026 · 47% similar
Discussion Highlights (3 comments)
knorker
Having the word "secure" as part of the product name is pretty brave, especially if you're Cisco.
VoidWhisperer
Is there an actual reason for this credential to exist, or did it just 'end up' there? (either an unfortunate artifact of testing in development work, or some other way)
nerdbaggy
There have been a TON of static creds on Cisco gear. Seems like a system wide engineering issue https://search.cisco.com/search?query=Static%20Credential%20...