Our takeCISA added CVE-2026-20316 to KEV: hard-coded password in Cisco Secure FMC, exploited as a zero-day. Patch if you run FMC (enterprises, MSPs); most smaller shops don't deploy it and can skip this.Cyber Resilience desk
Sources (4)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- helpnet · helpnet
What this means for you — Security leader:If you run Cisco Secure Firewall Management Center (FMC), treat CVE-2026-20316 as urgent: it is in CISA KEV with confirmed exploitation and allows unauthenticated remote login via a hard-coded low-privileged credential. Apply Cisco’s fixed releases or mitigations now and verify no unexpected FMC accounts or access.
What this means for you — Lean IT orgs:Most lean-IT shops do not run Cisco FMC themselves. If a provider manages your firewalls on FMC, ask them today whether they have patched CVE-2026-20316 and what evidence they can share.
What this means for you — MSP:Inventory every client with Cisco Secure Firewall Management Center; prioritize CVE-2026-20316—hard-coded credentials, unauthenticated remote access, actively exploited, now KEV. Patch or mitigate per Cisco, then check for unexpected logins on affected FMC instances.
What this means for you — Researcher:CVE-2026-20316 is a hard-coded password in Cisco FMC, added to KEV after confirmed in-the-wild use. Compare Cisco’s advisory (affected trains, fix versions, any credential rotation guidance) with the KEV due date and public exploit reporting.