Cisco Releases Hotfixes for Actively Exploited CVE-2026-20316 Zero-Day in Secure FMC Allowing Static Credential Access
A zero-day vulnerability tracked as CVE-2026-20316 is being actively exploited in Cisco Secure Firewall Management Center, enabling remote attackers to authenticate using hardcoded low-privilege credentials without prior authentication.
The flaw affects a critical component used in many corporate networks and carries a CVSS score of 5.3, yet Cisco has raised its internal severity rating to High because the initial access can be chained with additional vulnerabilities to expand privileges or reach elevated code execution.
Cisco has already distributed hotfixes for branches 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 with version-specific packages. Administrators are instructed to check license events in /var/log/messages and treat any appearance of the file /var/tmp/license.tmp as suspicious.
The same indicator is also associated with the related critical authentication bypass CVE-2026-20079, which may allow script execution to obtain root access. In environments exposed to both issues, patching should be performed as a combined remediation effort.
The most effective mitigation remains limiting exposure of the management interface to the internet by applying ACLs, VPN access and dedicated management networks. Organizations should also identify all FMC instances and their patch levels, rotate credentials and certificates after suspected activity, and enable telemetry focused on unusual sudo executions and commands involving license utilities such as paquete_info.pl.
U.S. federal civilian agencies have a remediation deadline of August 1, 2026 tied to the Known Exploited Vulnerabilities catalog.
Related articles
Secure Error Logging Practices to Prevent Information Leaks Across Java, Kotlin, JavaScript and Python
The article examines how improper error logging can expose sensitive details such as stack traces, file paths, library versions and database structures, enabling attackers to map applications and craft targeted exploits. It covers core logging levels from DEBUG to FATAL, mechanisms including text files, binary logs and databases, plus the roles of Trace ID and Correlation ID in tracing requests across microservices. Real-world vulnerable code examples in Flask and SQLite demonstrate direct exception output, manual traceback exposure and SQL error leakage that confirm technologies like Python 3.10 or SQLite usage. CWE categories including CWE-209, CWE-532, CWE-538 and CWE-1295 are referenced to classify risks of information disclosure through logs. Mitigation steps include stripping version headers in Nginx, sanitizing inputs with regular expressions, using OpenTelemetry for structured JSON logging and avoiding debug modes in production. The guidance stresses balancing detailed logs for incident response with protections against injection and reconnaissance.
Broadcom Patches Five Critical VMware Vulnerabilities Including CVSS 9.8 Authentication Bypass
Broadcom has released fixes for five vulnerabilities across multiple VMware products that could enable authentication bypass, remote code execution, and virtual machine escapes. The most severe issue, CVE-2026-59309 with a CVSS score of 9.8, resides in the VMware Directory Service component of vCenter and allows an attacker with network access to bypass authentication entirely. Successful compromise of vCenter grants control over hosts, virtual machines, networks, and storage, posing severe risks to enterprise environments. A second critical flaw, CVE-2026-47876, affects the VMXNET3 virtual adapter in ESX and permits an attacker with administrative privileges inside a guest VM to perform an out-of-bounds write and execute code on the hypervisor host. Additional patches address an unauthorized memory read in ESX, Workstation, and Fusion, along with insufficient logging that could conceal administrative actions. No workarounds exist, and administrators must apply the specified updates to vCenter, ESX, Cloud Foundation, Workstation, and Fusion.
Firefox JIT Vulnerability Exposes Tor Browser Users to Remote Code Execution
A high-severity flaw in Firefox's SpiderMonkey JavaScript engine allows remote code execution simply by visiting a malicious page, directly impacting Tor Browser users on unpatched versions. Registered as CVE-2026-10702, the vulnerability stems from incorrect memory handling in the JIT compiler that leaves a dangling reference to freed memory, enabling arbitrary read and write primitives. Researchers demonstrated successful exploitation that can compromise the browser's content rendering process and facilitate user deanonymization or OS-level attacks. The same issue served as the initial stage in the IonStack exploit chain against ARM64 Android devices, where it was chained with CVE-2026-43499 in the Linux kernel to achieve root privileges. Mozilla addressed the issue in Firefox 151.0.3, and the Tor Project rolled out corresponding fixes in Tor Browser 15.0.19, which also incorporates the latest Firefox ESR updates.
Google Releases Chrome Security Update Fixing 370 Vulnerabilities Including Seven Critical Issues
Google has issued a major security update for Chrome that addresses a total of 370 vulnerabilities across Windows, macOS, and Linux platforms. The update covers Chrome versions 151.0.7922.72 and 151.0.7922.71 and includes seven vulnerabilities rated Critical, the highest severity level. Among the critical flaws are multiple Use After Free issues affecting Compositing, Views, Skia, and Ozone components, plus input validation problems in Dawn and ANGLE graphics libraries and a race condition in the Updater component. In addition to the critical fixes, the release patches 71 High-severity vulnerabilities, 170 Medium-severity issues, and 122 Low-severity issues. The company plans a gradual rollout over the coming days and weeks. All listed CVEs from CVE-2026-17650 through CVE-2026-18019 have been resolved in this update.