CVE-2026-20316 is a hardcoded login baked into Cisco Secure Firewall Management Center. It has been exploited since early July, CISA added it to the KEV catalog on July 29, and the federal patch deadline is August 1.

Read the full story: Cisco FMC Hardcoded Credentials Exploited: Patch Due Today →

Transcript

Cisco's firewall management console ships with a username and password baked into the software. Same pair on every install. Attackers have been using it since early July. There's no exploit here, no memory corruption, nothing clever. You just log in. And what you get is the console that administers a whole fleet of firewalls. Read access to the access control policy, the network topology, every device name and version. That's the reconnaissance most intruders spend weeks assembling. Now here's the part that catches people out. The CVSS score is five point three. That's medium. Cisco's own impact rating says High, because the score measures one bug in isolation and cannot express that this one feeds the next attack. If you triage purely by score, you filed this below the line. CISA added it to the exploited catalog on July twenty ninth. The federal deadline is today. There is no configuration workaround, because the credential is in the binary. Install the hotfix.