Attackers are currently exploiting a backdoor in Cisco's Secure Firewall Management Center (FMC) software, which was created by hard-coded credentials for a low-privilege account. This vulnerability allows malicious actors to access vulnerable instances and sensitive data over the network. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of known exploited vulnerabilities. Cisco issued its own security advisory addressing the issue, noting that while the vulnerability has a medium risk rating (CVSS 5.3), they classify it as high risk due to potential combinations with other flaws in the FMC software that could escalate privileges. Cisco also updated a separate advisory related to another critical vulnerability (CVE-2026-20079, CVSS 10) that allowed script execution with root rights. However, Cisco did not explicitly mention active exploitation of the new vulnerability in their update, suggesting the advisory might have been rushed. There are no temporary workarounds available, and users are advised to apply the latest hotfixes immediately. Cisco provides specific versions of the hotfixes for different FMC software variants. The FMC
Bias read (Center): The article focuses on a technical cybersecurity vulnerability in Cisco's firewall management software and does not take a clear ideological stance. It reports on the discovery of the vulnerability, the response from CISA and Cisco, and the recommended actions for mitigation. The framing remains non





