CVE Tools

Cisco Secure FMC Zero-Day Exploited in the Wild

SecurityWeekBy Eduard Kovacs

Reported exploitedCisco Secure Firewall Management Center (FMC) Software

Our summary

Cisco has issued patches for a zero-day vulnerability in its Secure Firewall Management Center (FMC) software that is currently being exploited in real-world attacks. The flaw, identified as CVE-2026-20316, involves hardcoded default credentials for a low-privilege user account, enabling attackers to gain unauthorized access and retrieve sensitive data. Cisco labeled the issue 'high severity' and warned that it could be combined with other vulnerabilities to escalate privileges. Organizations are urged to apply updates immediately to mitigate risks.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store