This day 02:08 06:04 10:07 14:07 18:08 22:08
⚠ exploit status: CVE-2026-20316 · KEV·R
High  2026-07-30 06:04Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-07-30 — Cisco FMC hard-coded password exploited in the wild

Executive summary. CISA has added CVE-2026-20316KEV·R—a hard-coded password vulnerability in Cisco Secure Firewall Management Center (FMC)—to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw could allow unauthenticated attackers to gain administrative access to FMC appliances, which serve as the central management plane for Cisco's next-gen firewall estate. No other fresh findings were ingested in the last four hours; the rest of today's threat landscape remains unchanged from prior coverage.

Top items

Themes

Management-plane credentials remain a persistent weak point. A hard-coded password in a firewall management appliance is the same class of flaw that has plagued IoT devices, VPN concentrators, and network gear for years—but when the target is the centralised management console for an entire firewall fleet, the blast radius is dramatically larger. This joins a recent pattern of attackers targeting management interfaces (Palo Alto GlobalProtect, Fortinet FortiSandbox, SonicWall SMA) rather than individual endpoints.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db