Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, cisco, secure-fmc, static-credential, active-exploitation] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2026-20316 is a High-severity vulnerability in Cisco Secure FMC caused by static credentials for a low-privileged account, disclosed by Cisco on 29 July 2026 as actively exploited in attacks. Its impact is elevated because the access can be combined with other Secure FMC vulnerabilities (such as the CVSS-10.0 CVE-2026-20079 auth-bypass) to raise privileges. Cisco released the same hot fixes for both flaws, and shared IOCs suggesting both may have been used in the same intrusion activity.

Attribute Detail
CVE CVE-2026-20316
Type Static credentials for low-privileged account
Exploited In the wild (from late July 2026)
Source Cisco โ€” Tier 1/4

Source