Cisco Secure Firewall Management Center (FMC) software faces an actively exploited zero-day vulnerability, CVE-2026-20316, according to multiple reports. The issue is described as enabling a remote attacker to gain unauthorized access without authentication. SecurityWeek reports that the flaw can be exploited by a remote, unauthenticated attacker to log into affected devices. Bleeping Computer adds that Cisco warns the vulnerability involves static credentials and has been used in zero-day attacks to obtain access.

Separately, The Hacker News states that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog after reports of active exploitation. The Hacker News also cites a CVSS score of 5.3 for CVE-2026-20316.

Across the sources, the common points are that the vulnerability affects Cisco Secure FMC, is assigned CVE-2026-20316, is being exploited in real-world attacks, and can allow unauthorized access via remote exploitation without requiring authentication. Cisco and CISA actions indicate the issue is treated as a confirmed, currently exploited threat.