Cisco Secure FMC Zero-Day: Static Credentials Expose Sensitive Data
Cisco Secure Firewall Management Center (FMC) contains a hard-coded password vulnerability, tracked as CVE-2026-20316, that is being actively exploited to gain unauthorized access to sensitive data.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20316 to its Known Exploited Vulnerabilities (KEV) catalog following reports of zero-day exploitation. This vulnerability allows an unauthenticated, remote attacker to log in to an affected device using a low-privilege account due to the presence of static user credentials. Cisco has assigned this vulnerability a High severity rating, noting that it can be combined with other FMC vulnerabilities to elevate privileges. The attack surface is reduced if the FMC management interface does not have public internet access.
Cisco has not disclosed when the attacks began, who is behind them, or how the vulnerability is being exploited. The company recommends contacting them for a patch and reviewing access controls for affected systems. Security researcher Jimi Sebree of Horizon3.ai has been credited with discovering and reporting the flaw.
How 0Day mitigates this
Cisco Secure Firewall Management Center (FMC) is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.