Respond to the Cisco Secure FMC Static-Credential Vulnerability
Cisco disclosed CVE-2026-20316 on 29 July 2026: a static credential in the Cisco Secure Firewall Management Center (FMC) web interface can let an unauthenticated remote attacker sign in as a low-privileged user and access sensitive data. Cisco says it became aware of active exploitation in July, and CISA added the issue to its Known Exploited Vulnerabilities catalog on 29 July with a required-action date of 1 August for federal civilian agencies.