Security NEXTJuly 30, 2026🇯🇵Translated from Japanese

Cisco Secure Firewall Management Center Patched for Hardcoded Credential Vulnerability CVE-2026-20316 Already Exploited in the Wild

Cisco Systems has confirmed and fixed a new vulnerability in its Cisco Secure Firewall Management Center (FMC) firewall management product. The company disclosed the issue in a security advisory published on July 29, 2026, noting that the flaw had already been exploited in zero-day attacks.

The vulnerability, identified as CVE-2026-20316, stems from hardcoded credentials in the web interface. Attackers with remote access can authenticate and retrieve sensitive information. Although the CVSS v3.1 base score is 5.3, Cisco assigned a High severity rating because the flaw can be combined with other vulnerabilities to achieve privilege escalation.

Exploitation activity was first observed in July 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on the same day and instructed federal agencies to remediate by August 1, 2026.

Cisco emphasized that the static credentials provide low-privileged access that could serve as a stepping stone for more impactful attacks when chained with additional flaws. Customers are strongly advised to apply the available patches and review their FMC deployments for signs of compromise.

Related articles

Security NEXTVulnerabilities & Exploits

Broadcom Releases Critical Security Updates for VMware vCenter and ESX Vulnerabilities

Broadcom has issued security updates addressing five vulnerabilities in VMware vCenter and VMware ESX, including two rated as Critical. The flaws affect VMware Directory Service and Syslog server processing, potentially allowing authentication bypass and arbitrary code execution. CVE-2026-59309 enables attackers to bypass authentication over the network in VMware Directory Service, risking unauthorized system access. CVE-2026-59310 involves a path traversal issue in Syslog server handling that could lead to remote code execution. Multiple related products including VMware vSphere Foundation, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure are also impacted. The advisory VMSA-2026-0006 was published on July 29, 2026, with patches now available.

HispasecVulnerabilities & Exploits

Critical Gitea Vulnerability CVE-2026-60004 Allows Repository Writers to Execute Commands via Git Hooks

A critical vulnerability tracked as CVE-2026-60004 affects Gitea and enables remote command execution on the hosting server when an attacker possesses write permissions on a repository. The flaw is triggered by abusing Git hooks, which are small scripts that Git can automatically run at various points in the development workflow. Exploitation requires an authenticated account with write access, such as a collaborator or any role granted write permissions, making the issue particularly relevant for shared or multi-team repositories. Organizations that integrate Gitea into internal tooling face elevated risk because the server often has network visibility, access to shared storage, and proximity to sensitive credentials including CI/CD tokens and deployment keys. The recommended immediate actions include updating to the patched Gitea 1.27.1 release and auditing or disabling Git hooks wherever they are not strictly necessary. A publicly available proof-of-concept further increases operational urgency, prompting defenders to review permissions for external collaborators and rotate credentials if compromise is suspected.

Security NEXTVulnerabilities & Exploits

NVIDIA Patches Critical VIRTIO-Net Flaw in BlueField 3 Allowing VM Code Execution

NVIDIA has released a security update addressing a critical vulnerability in the VIRTIO-Net component used with its BlueField 3 DPU. The flaw, tracked as CVE-2026-65094, enables virtual machine users to execute arbitrary code within the VIRTIO-Net execution context through crafted messages that perform unauthorized memory writes. Originally assigned CVE-2025-33209, the identifier was later withdrawn and replaced. The issue was discovered internally by NVIDIA and carries a CVSS v3.1 base score of 9.0, rated Critical. Affected versions include VIRTIO-Net 25.10.6, 25.10.2, 24.10.50, and 23.10.23, with fixes available in subsequent releases. Organizations are advised to update immediately to mitigate the risk of code execution by untrusted VM tenants.

Security NEXTVulnerabilities & Exploits

Adobe Patches Critical Vulnerabilities in Bridge and Format Plugins

Adobe has released security updates addressing multiple critical vulnerabilities in Adobe Bridge and Adobe Format Plugins. The updates, published on July 28, 2026, resolve eight flaws in Adobe Bridge including search path issues tracked as CVE-2026-48395 and CVE-2026-48391, authorization problems under CVE-2026-48396 and CVE-2026-48390, plus path traversal CVE-2026-48374 and out-of-bounds write vulnerabilities CVE-2026-48392, CVE-2026-48393, and CVE-2026-48394. Adobe Format Plugins received a fix for the heap-based buffer overflow CVE-2026-48372 that could allow arbitrary code execution. The company published separate security advisories detailing the affected versions and remediation steps. These patches close attack vectors that could lead to remote code execution or unauthorized access when users open malicious files or rely on untrusted paths.