The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.
This vulnerability affects the Cisco Secure Firewall Management Center, previously known as the Firepower Management Center. It serves as a centralized platform for configuring, monitoring, and managing Cisco firewall deployments within enterprise environments.
CISA Adds Cisco Secure Firewall Management Flaw
CVE-2026-20316 is classified as a use of hard-coded password vulnerability (CWE-259). According to Cisco’s advisory, this issue could allow an unauthenticated remote attacker to log in to an affected FMC appliance using a low-privilege account.
Although the access level is limited, attackers could still use this account to access sensitive information stored or managed by the affected system.
CISA added this vulnerability to the KEV Catalog on July 29, 2026, and set an August 1, 2026, remediation deadline for U.S. federal civilian executive branch agencies. The short timeline reflects the immediate risk associated with vulnerabilities known to be exploited in real-world attacks.
While CISA has not identified CVE-2026-20316 as being involved in ransomware campaigns, the exploitation of internet-exposed firewall management infrastructures can pose significant operational and security risks.
FMC systems typically have visibility into firewall rules, network objects, VPN configurations, device inventories, event logs, and policy management workflows.
Even low-privileged access can provide attackers opportunities for reconnaissance or information that might aid in privilege escalation, lateral movement, or targeted attacks.
Organizations using Cisco Secure Firewall Management Center should promptly identify any potentially affected systems and consult Cisco’s guidance for available patches, mitigations, and impacted software releases. Security teams should prioritize appliances that are internet-facing or accessible from less trusted network segments.
CISA advises organizations to implement mitigations according to vendor instructions while complying with Binding Operational Directive BOD 26-04, which prioritizes security updates based on risk.
Where no mitigation is available, stakeholders should consider discontinuing the use of the affected product until a secure remediation path is established.
Additionally, security teams should review FMC authentication logs for any unusual successful logins, with a particular focus on activity from low-privileged or unexpected accounts.
Administrators need to investigate any anomalous configuration changes, newly created accounts, unexpected API activity, modifications to access control policies, and suspicious outbound connections from the management platform.
As a precautionary measure, organizations should restrict access to FMC management interfaces through network segmentation, allowlisting, VPN-only administrative access, and, where supported, multi-factor authentication. They should also ensure that management appliances are not directly exposed to the public internet unless necessary.
CISA further urges affected entities to comply with its forensic triage requirements and to evaluate each asset’s exposure to the internet.
Security teams should treat this KEV addition as a high-priority indicator that exploitation is not theoretical and should validate remediation across all FMC deployments, including standby appliances and disaster recovery environments.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

