Cisco FMC Zero-Day Under Active Exploitation, CISA Deadline Today
A zero-day flaw in Cisco's Secure Firewall Management Center is under active exploitation, letting unauthenticated attackers log in with a low-privilege account. CISA added it to its exploited vulnerabilities catalog and set an August 1st patch deadline, according to The Hacker N
Cisco Secure Firewall Management Center (FMC) Software has a static credential vulnerability, tracked as CVE-2026-20316 with a CVSS score of 5.3, that is under active exploitation. The flaw lets an unauthenticated remote attacker log in using a built-in low-privilege account to access sensitive data. Cisco rates it high severity because it can be chained with a separate critical flaw, CVE-2026-20079 (CVSS 10.0), an authentication bypass that can lead to full remote code execution. The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog and set an August 1, 2026 patch deadline for federal agencies. Cisco released hot fixes for software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Source: The Hacker News, CISA, SecurityWeek.