Security · 2h ago
Cisco FMC Zero-Day Exploited in Wild; CISA Adds to KEV Catalog
CISA added CVE-2026-20316, a zero-day in Cisco Secure FMC Software, to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The flaw (CVSS 5.3) allows unauthenticated remote attackers to log into devices using static credentials. Cisco has not yet released a patch, leaving systems exposed.
Meridian48 take
While the CVSS score is moderate, active exploitation and static credentials make this a serious operational risk for enterprises relying on Cisco FMC.
Read the full reporting
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data →
The Hacker News
cisco-fmczero-day