Cisco Firewall Zero-Day Under Active Exploit, CISA Warns
Static credentials in Firewall Management Center software allow unauthenticated remote access; U.S. agency adds flaw to mandatory patch list.
The U.S. Cybersecurity and Infrastructure Security Agency added a Cisco Secure Firewall Management Center vulnerability to its Known Exploited Vulnerabilities catalog Wednesday, confirming active exploitation in the wild.
The flaw, tracked as CVE-2026-20316 with a CVSS score of 5.3, permits unauthenticated remote attackers to log into affected systems. The vulnerability stems from static credentials embedded in the FMC software—a design flaw that bypasses normal authentication controls. CISA's KEV listing triggers mandatory patching deadlines for federal agencies and signals elevated risk for private sector operators using the platform.
Cisco Secure Firewall Management Center is deployed widely across enterprise and government networks to centrally manage firewall policies and security posture. The zero-day designation indicates adversaries were exploiting the flaw before Cisco disclosed it publicly, compressing the window for defensive action.
- 01Federal agencies face binding patch deadlines under CISA directive; non-compliance risks audit findings.
- 02Enterprises using Cisco FMC should assume reconnaissance or compromise attempts are underway.
- 03Incident response teams must audit FMC access logs for anomalous authentication events.
- 04Supply chain and managed service providers relying on FMC face downstream client exposure.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.