Cookie Consent by Free Privacy Policy Generator

Cisco Secure Firewall Management Center zero-day actively exploited

CISA has added a newly disclosed Cisco vulnerability to its Known Exploited Vulnerabilities catalogue following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-20316, affects Cisco Secure Firewall Management Center software and allows an unauthenticated remote attacker to log into affected devices using hard-coded credentials. Cisco disclosed the flaw on 29 July 2026, and CISA's addition to the KEV catalogue confirms that exploitation is already occurring. The vulnerability has a CVSS score of 5.3, and Cisco has released patches for affected versions. SecurityWeek and The Hacker News both report that the flaw could allow attackers to access sensitive configuration data and potentially pivot further into managed environments.

Why this matters for UK organisations

For UK organisations using Cisco Secure Firewall Management Center, this is a significant operational risk. The use of hard-coded credentials is a well-understood weakness, but it remains a common attack vector because it requires no sophisticated exploitation technique and can be automated at scale. Firewall management platforms are high-value targets because they provide visibility and control over network segmentation, access policies and traffic flows. Compromise of these systems can allow attackers to disable logging, modify rules, or gain insight into network architecture that supports further lateral movement. The fact that exploitation is already occurring means this is not a theoretical risk, and organisations should assume that scanning and exploitation attempts are underway. For organisations in sectors such as finance, healthcare, critical infrastructure and managed services, where firewall management platforms control access to sensitive systems and data, the operational impact of a compromise could be significant. The vulnerability also highlights the importance of defence in depth, even security infrastructure requires segmentation, monitoring and access controls.

What to review

Organisations running Cisco Secure Firewall Management Center should apply the available patches as a priority. It is also worth reviewing whether firewall management interfaces are appropriately segmented, whether access is restricted to authorised networks or users, and whether logging and alerting for management plane access is functioning and reviewed regularly. Organisations should confirm that firewall management systems are not directly exposed to the internet, and that access is controlled through VPNs, jump hosts or other secure access methods. It is also sensible to review whether firewall configuration changes are logged, reviewed and subject to change control processes, and whether those logs are retained and monitored for anomalies. For organisations that cannot immediately patch, consider whether temporary mitigations such as network segmentation or access restrictions can reduce exposure until patches can be applied.

Source: SecurityWeek

News and blog posts
Today's brief focuses on practical security foundations that matter when...
The National Cyber Security Centre has published new guidance aimed at helping...
CISA has added a newly disclosed Cisco vulnerability to its Known Exploited...
OpenAI has disclosed that a rogue AI agent, previously reported to have...