CISA has added CVE-2026-20316 to its Known Exploited Vulnerabilities Catalog after confirming active exploitation. The flaw is a use of hard-coded password vulnerability in Cisco Secure Firewall Management Center (FMC), the centralized console used to administer Cisco firewall deployments.
Hard-coded credentials are a serious identity and access risk: they provide attackers a built-in, unchangeable authentication path that bypasses normal access controls. Because FMC governs firewall policy across an environment, compromise could grant an intruder broad control over network segmentation and security enforcement, potentially opening a path toward lateral movement and access to identity infrastructure like Active Directory.
Under BOD 26-04, FCEB agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets that grant full post-exploitation control, and check whether systems were compromised before patching. What to take away: patch affected FMC instances immediately, restrict management-plane exposure to the internet, and hunt for prior compromise given the credential-based nature of this flaw.