Skip to content

Cisco Secure Firewall Management Center: Zero-Day Vulnerability Actively Exploited

Bottom line: CVE-2026-20316 in Cisco FMC is being actively exploited and enables unauthenticated access to sensitive data through hardcoded credentials.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20316 to its catalog of actively exploited vulnerabilities. The vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote access through static login credentials.

CISA added the vulnerability CVE-2026-20316 (CVSS score 5.3) to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday. The flaw affects Cisco Secure Firewall Management Center (FMC) software and is already being exploited in the field, according to security research sources. It allows unauthenticated attackers to log in remotely.

Access is facilitated by static, hardcoded login credentials present in the FMC software. This allows potential attackers not only authentication but also access to sensitive data within the system. Particularly in environments where FMC serves as the central management instance for firewall policies, this presents a significant risk.

CISOs should prioritize reviewing affected FMC instances and apply outstanding security updates from Cisco. Inclusion in the KEV catalog signals that government agencies and critical infrastructure operators as well as supply chains consider this risk acute.


Source: thehackernews.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: