Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco Secure FMC Zero-Day Exploited in the Wild
Cisco has patched CVE-2026-20316, an actively exploited zero-day in Secure Firewall Management Center that lets attackers use default credentials to access sensitive data. CISA added the flaw to its KEV catalog, and Cisco shared IoCs while warning the issue can be chained with other FMC vulnerabilities to gain higher privileges. #CVE-2026-20316 #Cisco #SecureFirewallManagementCenter #CISA #Horizon3ai

Keypoints

  • Cisco patched an actively exploited zero-day in Secure Firewall Management Center.
  • The flaw, tracked as CVE-2026-20316, involves static credentials for a low-privilege account.
  • An attacker could use the issue to log in and access sensitive data.
  • Cisco warned the bug may be chained with other FMC flaws to escalate privileges.
  • CISA added CVE-2026-20316 to its KEV catalog and set an August 1 deadline for government agencies.

Read More: https://www.securityweek.com/cisco-secure-fmc-zero-day-exploited-in-the-wild/