Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Our summary
CISA has added a new vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-20316, allows unauthenticated attackers to log in using hard-coded low-privilege credentials and potentially access sensitive data. Cisco rates the issue as High severity due to potential privilege escalation when combined with other vulnerabilities. Customers are advised to update to one of the listed hotfix versions immediately.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.