SECURITYTHE HACKER NEWS
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
CISA added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its KEV catalog due to active exploitation. The flaw, CVE-2026-20316 (CVSS score: 5.3), allows unauthenticated remote attackers to log in and potentially expose sensitive data.
Mentioned
Related Signal
Adjacent reporting
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
- Cisco zero-day under ongoing attack by persistent threat group
- Cisco customers encounter another SD-WAN zero-day under attack
- CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
- CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines