Cisco Secure Firewall Management Center zero-day CVE-2026-20316 under active exploitation, CISA patch deadline already passed
A hard-coded password flaw in Cisco Secure Firewall Management Center is under active exploitation, letting unauthenticated attackers log in via a low-privilege account and pull data. Cisco $CSCO says exploitation began in July. CISA added it to its KEV catalog, patch deadline Au
A vulnerability in Cisco's Secure Firewall Management Center is being actively exploited in the wild, according to Cisco $CSCO and CISA. The flaw, tracked as CVE-2026-20316, is a hard-coded, low-privilege set of credentials built into the FMC web interface. That means a remote attacker with no valid account of their own can log in and pull sensitive data straight from an affected device. Researchers have also shown the bug can be chained with other known FMC flaws to escalate from that low-privilege foothold into deeper access. Cisco says it first became aware of exploitation attempts in July. CISA responded by adding the vulnerability to its Known Exploited Vulnerabilities catalog and set an August 1 deadline for federal agencies to patch, a date that has already passed. FMC is the central management console for Cisco's Secure Firewall product line, so any organization still running an unpatched instance is effectively leaving a master key exposed on the public internet. Enterprises, government networks and managed security providers that rely on Cisco firewalls for perimeter defense have the most at stake: a compromised FMC console can cascade into visibility over every firewall it manages. Source: The Hacker News, CISA Known Exploited Vulnerabilities catalog.