CISA Adds Cisco FMC Flaw to Hacks List as Attackers Use Static Credentials
The U.S. Cybersecurity and Infrastructure Security Agency has added a Cisco Systems vulnerability to its list of bugs confirmed to be exploited in the wild, raising the risk for Firepower Management Center users. The zero-day flaw, identified as CVE-2026-20316, allows unauthenticated remote attackers to log in using static credentials to access sensitive data through a low-privilege account.
Cisco warns that the vulnerability can be chained with other flaws in the management software to elevate privileges. Administrators are advised to apply immediate mitigations to secure the network infrastructure while a full patch is developed.
From the sources (2 posts)
@thehackersnews⚠️ Attackers are exploiting Cisco FMC zero-day CVE-2026-20316. The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account. Cisco warns it can be chained with other FMC fl
@threataft🚨 CISA KEV: Cisco Secure FMC Hardcoded Credential — Active Exploitation CVE-2026-20316: Unauthenticated attackers can log in with static credentials and escalate privileges. → #cybersecurity #infosec #Cisco #CISAK