Cisco Systems is under pressure as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has set an August 1, 2026, deadline for federal agencies to apply fixes for a zero-day vulnerability in its Secure Firewall Management Center (FMC) software. The vulnerability, tracked as CVE-2026-20316, is due to static user credentials that could allow an unauthenticated, remote attacker to log in with a low-privilege account and access sensitive data.

Cisco confirmed in late July that it was aware of active exploitation of this flaw and has released software updates to address it. While the vulnerability has a base CVSS score of 5.3, Cisco has given it a "High" Security Impact Rating because it can potentially be combined with other flaws to escalate privileges. CISA's inclusion of the flaw in its Known Exploited Vulnerabilities (KEV) catalog underscores the seriousness of the threat to government and corporate networks.