CISA is warning organizations about a critical zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC), tracked as CVE-2026-20316. The flaw stems from a hard-coded password baked into the software, letting unauthenticated attackers log in with low-privilege access — no credentials needed.
Once inside, attackers can view firewall policies, security rules, and event logs, potentially setting the stage for deeper network compromise. CISA is urging immediate patching under BOD 26-04 guidelines. If no fix is available, they recommend taking the product offline entirely. Organizations should also audit FMC access logs now for signs of unauthorized logins.
Source: Cybersecurity News