Cisco FMC ships with hardcoded credentials — two zero-days exploited in the wild, one CVSS 10.0
On July 29, 2026, Cisco disclosed two zero-day vulnerabilities in Secure Firewall Management Center: static hardcoded credentials (CVE-2026-20316) and a CVSS 10.0 authentication bypass (CVE-2026-20079). Check your logs immediately — both flaws share the same indicator of compromise.