Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Summary

CISA has added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-20316, allows unauthenticated remote attackers to log in and could expose sensitive data.

IFF Assessment

FOE

This vulnerability allows unauthenticated remote attackers to gain access and potentially expose sensitive data, posing a significant threat to defenders.

Severity

5.3 Medium

The CVSS score of 5.3 indicates a moderate severity. The vulnerability allows for remote, unauthenticated access and potential exposure of sensitive data, which are significant factors in its scoring.

CISA KEV: Listed as actively exploited. Federal patch due: August 01, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or implementing mitigations for Cisco FMC devices immediately due to active exploitation of this zero-day vulnerability. Monitoring network traffic for unusual access patterns to FMC and ensuring strong credential management are crucial steps to prevent exploitation.

Read Full Story →