“Cisco FMC vulnerability” — 15 distilled results

Cisco Secure Firewall vulnerability actively exploited in wild

CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, citing active exploitation. The high-severity flaw in Cisco Secure Firewall Management Center allows unauthenticated remote login via hardcoded credentials embedded in the web interface, affecting versions 7.0 through 10.0.

Multiple zero-day exploits in enterprise security tools

Check Point's SmartConsole GUI admin panel has an actively exploited zero-day authentication bypass (CVE-2026-16232, CVSS 9.3) that grants full admin access to Security Management servers; a patch has been released. Cisco's Secure FMC also faces an actively exploited zero-day involving static credentials.

Cisco Firewall Management Center vulnerabilities actively exploited

Cisco Talos confirmed on September 10, 2026, that CVE-2026-20079 and CVE-2026-20316, maximum-severity vulnerabilities in Cisco Secure Firewall Management Center (FMC), were being actively exploited by state-sponsored actors, ransomware gangs, and financially motivated threat groups. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities list on September 9.

CISA adds multiple critical vulnerabilities to known exploited catalog

Between September 8 and 11, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added six critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Microsoft Windows, GitLab, JFrog Artifactory, and N-able N-central that allow remote code execution and privilege escalation. Active exploitation of these vulnerabilities has been documented.

json:cisa-kev 20d ago