Cisco FMC static credential vulnerability exploited as a zero-day
nyku
11 points
3 comments
July 30, 2026
Related Discussions
Found 5 related stories in 589.5ms across 15,510 title embeddings via pgvector HNSW
- CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV slvnx · 31 pts · July 16, 2026 · 56% similar
- Hackers now exploit critical F5 BIG-IP flaw in attacks, patch now Brajeshwar · 21 pts · March 30, 2026 · 54% similar
- 24,650 internet-accessible BMCs leak password-derived hashes before login ilreb · 20 pts · July 28, 2026 · 54% similar
- Cisco source code stolen in Trivy-linked dev environment breach _____k · 22 pts · March 31, 2026 · 53% similar
- CPanel and WHM Authentication Bypass – CVE-2026-41940 zikani_03 · 79 pts · April 30, 2026 · 53% similar
Discussion Highlights (3 comments)
knorker
Having the word "secure" as part of the product name is pretty brave, especially if you're Cisco.
VoidWhisperer
Is there an actual reason for this credential to exist, or did it just 'end up' there? (either an unfortunate artifact of testing in development work, or some other way)
nerdbaggy
There have been a TON of static creds on Cisco gear. Seems like a system wide engineering issue https://search.cisco.com/search?query=Static%20Credential%20...