CISCO has announced patches for a high-severity zero-day vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC), which allows attackers to exploit default credentials to access sensitive data. This vulnerability has been actively exploited since July and can potentially be chained with other FMC vulnerabilities to escalate privileges.
Cisco advises organizations to limit public internet access to the FMC management interface to reduce the attack surface, and has provided indicators of compromise (IoCs) for detection. Additionally, CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging government entities to address it by August 1. Cisco also updated its advisory for another critical FMC vulnerability patched earlier.