← Back to Feed
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
CVE-2026-20316
July 30, 2026 · The Hacker News · Severity: CRITICAL
CISA added CVE-2026-20316 affecting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation. The vulnerability (CVSS 5.3) stems from static user credentials for a low-privileged account, allowing unauthenticated remote attackers to log in and access sensitive data. Cisco notes the attack surface is reduced if the FMC management interface lacks public internet access. CISA ordered federal agencies to remediate by August 20, 2026. No workaround is available; the fix requires a software update.
Key Takeaways
- CVE-2026-20316 in Cisco FMC involves hardcoded static credentials for a low-privileged account, enabling unauthenticated remote access to sensitive data.
- The vulnerability is under active exploitation, and CISA has added it to the KEV catalog with a remediation deadline of August 20, 2026 for federal agencies.
- Exposing the FMC management interface to the public internet significantly increases the attack surface; restricting access reduces risk.