Cisco on Wednesday announced patches for an actively exploited zero-day vulnerability affecting its Secure Firewall Management Center (FMC) product.
The security hole, tracked as CVE-2026-20316, has been described as a static credential issue. Specifically, an attacker can leverage default credentials for a low-privilege user account to log into vulnerable devices and access sensitive data.
Cisco assigned a ‘high severity’ rating to the vulnerability, noting that it can be chained with other FMC flaws to escalate privileges.
“If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced,” Cisco said in its advisory.
The networking giant said it became aware of the active exploitation of CVE-2026-20316 in July, and it has made available indicators of compromise (IoCs) to enable organizations to detect attacks.






