CVE Tools

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The Hacker NewsBy The Hacker News

Our summary

CISA has added a new vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-20316, allows unauthenticated attackers to log in using hard-coded low-privilege credentials and potentially access sensitive data. Cisco rates the issue as High severity due to potential privilege escalation when combined with other vulnerabilities. Customers are advised to update to one of the listed hotfix versions immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store