🟠 High  |  Source: The Hacker News


A zero-day vulnerability in Cisco’s Firewall Management Center (FMC) software, tracked as CVE-2026-20316, allows unauthenticated remote attackers to gain access and has been added to CISA’s Known Exploited Vulnerabilities catalogue. The flaw, combined with the risk of static hardcoded credentials, could expose sensitive firewall configuration data and network infrastructure details. Active exploitation in the wild makes this an urgent patching priority for any organisation running Cisco FMC.

Security Architect’s Take: Immediately audit your Cisco FMC deployments, apply available patches or vendor mitigations without delay, and review firewall management interfaces to ensure they are not exposed to the internet — restrict access to FMC consoles to trusted management networks or VPNs as a compensating control.

Original advisory: Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data