Zero-day in Cisco Secure FMC Exploited; Patches Released
CVE-2026-20316 allows logins with default low-privilege credentials on Cisco Secure Firewall Management Center; CISA ordered fixes by Aug. 1.
Cisco released patches and indicators of compromise after confirming active exploitation of a zero-day vulnerability in its Secure Firewall Management Center (FMC), tracked as CVE-2026-20316. Attackers can authenticate with a built-in low-privilege account using its default password and access sensitive data on affected systems.
The company classified the flaw as a static credential vulnerability and assigned it a high severity rating. The advisory explains that an attacker with access to the low-privilege account can view or steal data and may combine this issue with other FMC vulnerabilities to obtain higher privileges. Systems whose FMC management interfaces are not exposed to the public internet have a smaller attack surface.
Cisco reported awareness of in-the-wild exploitation in July and made available IoCs to help organizations detect possible compromises. Security firm Horizon3.ai is credited with reporting the vulnerability; the firm has not released additional technical details. No public technical analysis or attribution for the active exploitation has been published.
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog and instructed federal civilian agencies to remediate the issue by Aug. 1. Inclusion in the catalog flags the defect as observed in real-world attacks and places the fix on a government deadline.
In a related update, Cisco revised guidance for CVE-2026-20079, a separate FMC vulnerability patched in March. While that earlier patch did not include reports of active exploitation, Cisco provided IoCs for detection. Over recent months the vendor has tracked exploitation of multiple product flaws, including issues in Catalyst SD-WAN Manager and Unified Communications Manager.
Organizations running Cisco Secure Firewall Management Center should install the vendor patches immediately and remove or change default passwords for built-in accounts. Cisco’s advisory recommends reviewing published IoCs for signs of compromise and limiting public internet access to FMC management interfaces to reduce exposure. Network teams are advised to combine credential changes with monitoring of administrative logins for unusual activity.
Security teams are advised to follow Cisco’s updated advisories and CISA guidance for detection and mitigation while awaiting further technical details from the reporter and the vendor.








