
CISA Adds Actively Exploited Cisco FMC Zero-Day Vulnerability to KEV Catalog
CybersecurityVulnerabilitiesHackingNetworkSecurity
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday. The flaw, tracked as CVE-2026-20316 with a CVSS score of 5.3, allows an unauthenticated, remote attacker to log in under certain conditions. Reports confirm active exploitation of this vulnerability in the wild. The issue specifically affects Cisco FMC, a centralized management platform for firewall policies and security events. No additional technical details or mitigation steps were provided in the notice.