www.securityweek.com 7/30/2026, 6:50:13 AM · external

Cisco patches zero day flaw in Secure FMC after July attacks

Cisco patches zero day flaw in Secure FMC after July attacks
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

CISCO has announced patches for a high-severity zero-day vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC), which allows attackers to exploit default credentials to access sensitive data. This vulnerability has been actively exploited since July and can potentially be chained with other FMC vulnerabilities to escalate privileges.

Cisco advises organizations to limit public internet access to the FMC management interface to reduce the attack surface, and has provided indicators of compromise (IoCs) for detection. Additionally, CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging government entities to address it by August 1. Cisco also updated its advisory for another critical FMC vulnerability patched earlier.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline