CISA Adds Cisco Secure Firewall Flaw to Known Exploited Vulnerabilities Catalog
CISA has added CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of CVE-2026-20316 to its catalog of Known Exploited Vulnerabilities (KEV). This critical flaw resides within Cisco Secure Firewall Management Center and involves the use of a hard-coded password, a common vector for malicious cyber actors.
The inclusion in the KEV catalog signifies that CISA has confirmed active exploitation of this vulnerability in the wild. This designation triggers specific requirements for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive (BOD) 26-04. This directive mandates the prioritization of patching for vulnerabilities listed in the KEV catalog on publicly exposed assets that could lead to full system control post-exploitation.
BOD 26-04 emphasizes a risk-based approach to vulnerability management, urging federal agencies to address high-risk vulnerabilities, such as CVE-2026-20316, with urgency. The directive also outlines expectations for agencies to check for signs of compromise on affected systems prior to applying patches, a crucial step in understanding the full impact of an exploit.
While BOD 26-04 specifically targets FCEB agencies, CISA strongly encourages all organizations, including those in the private sector, to adopt similar risk-based vulnerability management practices. Prioritizing the remediation of vulnerabilities listed in the KEV catalog is a key recommendation for enhancing overall cybersecurity posture.
The hard-coded password vulnerability in Cisco Secure Firewall Management Center presents a significant risk, potentially allowing unauthorized access and control over critical network security infrastructure. The active exploitation observed by CISA underscores the immediate threat posed by this flaw.
CISA continues to actively monitor the threat landscape and will add further vulnerabilities to the KEV catalog as evidence of exploitation emerges. Organizations are advised to regularly consult the KEV catalog and CISA alerts for the latest information on critical vulnerabilities and recommended actions.
CISA also provides a nomination form for the public to submit vulnerabilities that they believe warrant inclusion in the KEV catalog. To be considered, a vulnerability must have a confirmed CVE ID, demonstrable evidence of exploitation, and clear guidance on how to mitigate or patch the issue.
CISA has officially added CVE-2026-20316, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) related to static credentials, to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion confirms that the flaw is being actively exploited in the wild, underscoring the urgency for organizations to apply Cisco's released hot fixes.