Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
What happened
CISA has added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following zero-day attacks against Cisco Secure Firewall Management Center. The flaw allows unauthenticated remote attackers to log into affected devices using static credentials.
Why it ranks #1
Confirmed active exploitation of a network management platform listed in CISA KEV takes top priority over all other vulnerabilities and incidents.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Update Cisco Secure FMC software to the latest patched version immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed