Cisco Secure FMC Zero-Day Vulnerability Exploited in the Wild
Cisco disclosed patches for a zero-day vulnerability impacting its Secure Firewall Management Center (FMC) platform, which has been actively exploited in real-world scenarios.
Vulnerability Details
The flaw, designated CVE-2026-20316, involves a static credential configuration that allows unauthorized access to vulnerable systems. Attackers can exploit default login credentials for a low-privilege user account to gain entry to affected devices and retrieve sensitive information. The vulnerability carries a high severity rating, with Cisco noting that it could be combined with other FMC flaws to escalate privileges.
Exploitation and Risk
The company emphasized that restricting public internet access to the FMC management interface significantly reduces the risk associated with this flaw. Cisco first identified active exploitation of CVE-2026-20316 in July and has since released indicators of compromise (IoCs) to assist organizations in identifying potential breaches.
Researcher and CISA Involvement
A researcher from Horizon3.ai reported the vulnerability, though the firm has not provided further details about the specific exploit. No public records describe the nature of attacks leveraging this flaw. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-20316 in its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to resolve the issue by August 1.
According to the provided content, the researcher from Horizon3.ai reported the vulnerability, though the firm has not provided further details about the specific exploit.
Advisory Updates and Recent Threats
Cisco also updated its advisory for CVE-2026-20079, a critical FMC vulnerability addressed in March. While no evidence of in-the-wild exploitation has been confirmed for this second flaw, IoCs remain available for threat detection. Over the past several months, Cisco has detected exploitation attempts targeting multiple products, including the Catalyst SD-WAN Manager and Unified Communications Manager.
Continued Monitoring and Response
The company continues to monitor and respond to emerging threats across its portfolio.
