CVE Tools
Back to feed

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

CISA has added a new vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-20316, allows unauthenticated attackers to log in using hard-coded low-privilege credentials and potentially access sensitive data. Cisco rates the issue as High severity due to potential privilege escalation when combined with other vulnerabilities. Customers are advised to update to one of the listed hotfix versions immediately.