Cisco Secure FMC Zero-Day Vulnerability Exploited in the Wild

www.news4hackers.com-cisco-secure-fmc-zero-day-vulnerability-exploited-in-the-wild-cisco-secure-fmc-zero-day-vulnerability-exploited-in-the-wild

Cisco disclosed patches for a zero-day vulnerability impacting its Secure Firewall Management Center (FMC) platform, which has been actively exploited in real-world scenarios.

Vulnerability Details

The flaw, designated CVE-2026-20316, involves a static credential configuration that allows unauthorized access to vulnerable systems. Attackers can exploit default login credentials for a low-privilege user account to gain entry to affected devices and retrieve sensitive information. The vulnerability carries a high severity rating, with Cisco noting that it could be combined with other FMC flaws to escalate privileges.

Exploitation and Risk

The company emphasized that restricting public internet access to the FMC management interface significantly reduces the risk associated with this flaw. Cisco first identified active exploitation of CVE-2026-20316 in July and has since released indicators of compromise (IoCs) to assist organizations in identifying potential breaches.

Researcher and CISA Involvement

A researcher from Horizon3.ai reported the vulnerability, though the firm has not provided further details about the specific exploit. No public records describe the nature of attacks leveraging this flaw. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-20316 in its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to resolve the issue by August 1.

According to the provided content, the researcher from Horizon3.ai reported the vulnerability, though the firm has not provided further details about the specific exploit.

Advisory Updates and Recent Threats

Cisco also updated its advisory for CVE-2026-20079, a critical FMC vulnerability addressed in March. While no evidence of in-the-wild exploitation has been confirmed for this second flaw, IoCs remain available for threat detection. Over the past several months, Cisco has detected exploitation attempts targeting multiple products, including the Catalyst SD-WAN Manager and Unified Communications Manager.

Continued Monitoring and Response

The company continues to monitor and respond to emerging threats across its portfolio.


Blog Image

About Author

en_USEnglish