Cisco Secure FMC Zero-Day Exploited in the Wild
criticalDetails
A static credential vulnerability, CVE-2026-20316, allows a remote, unauthenticated attacker to log into the Cisco Secure Firewall Management Center (FMC) software. This flaw was exploited as a zero-day before a patch was available.
Affected Systems
Cisco Secure Firewall Management Center (FMC)
Potential Impact
Successful exploitation could allow an attacker to gain unauthorized access to the firewall management console, potentially leading to device takeover, security policy manipulation, and exposure of sensitive network data.
Mitigations
Apply patches immediately. This vulnerability is on the CISA KEV list with a required remediation date of August 1, 2026.