Cisco firewalls under fire from new zero-day vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of a zero-day vulnerability in Cisco’s firewall management suite.
Designated as CVE-2026-20316 and affecting Cisco Secure Firewall Management Center (FMC), the flaw allows unauthenticated, remote login to an affected device through a low-privileged account, providing access to data within the impacted systems.
Cisco advised users to download hot fixes to various versions of Secure FMC, while assigning a security impact rating (SIR) of “high” to the flaw as it could be used to leverage other Secure FMC Software vulnerabilities to elevate security privileges.
The firm added that customers should rotate all user credentials, keys, and certificates on the Cisco Secure FMC device due to ongoing active exploitation of the vulnerability.
The flaw does not affect Cloud-Delivered FMC (cdFMC), Firewall Device Manager (FDM), Secure Firewall Adaptive Security Appliance (ASA) Software, Secure Firewall Threat Defense (FTD) Software, nor Security Cloud Control (SCC).