CISA has added CVE-2026-20316, a flaw in Cisco Secure Firewall Management Center (FMC) Software, to its KEV catalog after reports of zero-day exploitation. Cisco says the issue stems from static credentials in a low-privilege account and may be chained with CVE-2026-20079 to increase privileges and potentially reach code execution. #Cisco #CISACVE-2026-20316 #CVE-2026-20079
Keypoints
- CISA added CVE-2026-20316 to its KEV catalog after active exploitation was reported.
- The flaw affects Cisco Secure Firewall Management Center Software and involves static user credentials.
- An unauthenticated attacker may log in with a low-privilege account and access sensitive data.
- Cisco says the issue is less exposed when the FMC management interface is not public-facing.
- Cisco also updated CVE-2026-20079 with new indicators of compromise and hot fixes.
Read More: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html