CISA has added CVE‑2026‑20316 to its Known Exploited Vulnerabilities catalogue, affecting Cisco’s Secure Firewall Management Center (FMC). The vulnerability, named Cisco Secure Firewall Management Center Use of Hard‑coded Password Vulnerability, allows an unauthenticated remote attacker to log in using a low‑privileged account and access sensitive data.
The flaw is a hard‑coded credential issue in the FMC web interface that can be exploited over the network without authentication. It has a CVSS v3.1 base score of 5.3 (MEDIUM) and a patch is available from Cisco. Successful exploitation could lead to unauthorized viewing or modification of firewall policies and logs.
Active exploitation has been confirmed, which is the basis for the KEV entry; there is no public record of ransomware use tied to this CVE. CISA has set a remediation deadline of 1 August 2026 for federal agencies to address the issue.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26‑04 patching guidelines. While the directive binds FCEB agencies, all organisations should review their exposure to this vulnerability.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-20316 and the CISA KEV catalogue.