THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in Cisco Secure Firewall Management Center (FMC) Software, identified as CVE-2026-20316 with a CVSS score of 5.3, to its Known Exploited Vulnerabilities catalog. This flaw allows unauthenticated remote attackers to access sensitive information by exploiting hardcoded credentials for a low-privileged user account.
Cisco has released hotfixes for multiple software versions and has confirmed active exploitation of this vulnerability. CISA emphasizes the urgency for federal agencies and organizations to address this flaw to protect their networks.