CISA KEV: Cisco FMC CVE-2026-20316 Security Update Checklist
July 29, 2026
Priority: patch Cisco Secure Firewall Management Center (FMC) software promptly. CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, 2026, and Cisco reports active exploitation. This issue can let an unauthenticated remote attacker sign in to an affected self-managed FMC with a low-privileged account and access sensitive information.
This is an FMC management-plane issue, not a routine firewall rule change. Treat an internet-reachable management interface as urgent until the Cisco-supported fixed release is in place and your team has completed its normal recovery checks.
What is affected
Cisco’s advisory applies to Cisco Secure Firewall Management Center software. Cisco lists Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense, and Security Cloud Control as not affected by this specific issue. Confirm the exact product and installed software release against Cisco’s advisory before scheduling work.
Immediate defensive checklist
- Identify every self-managed FMC, its installed release, responsible owner, and whether its management interface can be reached from the public internet.
- Reduce unnecessary management-plane exposure through your approved network-access controls while the maintenance change is prepared. Keep emergency access limited to the administrators who need it.
- Use Cisco’s advisory to select the appropriate fixed software release for each affected system. Do not substitute an unverified image, archive, or third-party fix.
- Schedule the upgrade through the normal change process. Record the target release, maintenance window, rollback decision owner, and the firewall services that need verification afterward.
- After the update, confirm the installed version, administrator access, managed-device connectivity, policy deployment health, logging, and alerting.
Why the KEV listing matters
CISA’s KEV catalog is reserved for vulnerabilities with evidence of exploitation. The catalog entry for CVE-2026-20316 asks organizations to follow vendor mitigations, evaluate each asset’s internet exposure, and use the applicable risk-based patching guidance. Cisco also states that it became aware of active exploitation in July 2026.
Cisco assigned the issue a CVSS base score of 5.3 but a High Security Impact Rating because it may be combined with other FMC vulnerabilities to raise privileges. The KEV listing and active-exploitation status should drive the patch priority rather than the base score alone.
Recovery and verification after patching
If your team suspects compromise, engage Cisco TAC and your incident-response process. Cisco recommends rotating user credentials, keys, and certificates on the affected FMC as part of recovery. Preserve your normal evidence-handling process and do not treat a successful software update as proof that no review is needed.
- Confirm that the appliance is on Cisco’s applicable fixed release.
- Review administrator access and connected-device health through the normal management console.
- Verify that planned policy deployments and logging are functioning before closing the maintenance change.
- Document exposure changes, the completed update, recovery actions, and any follow-up work for the security owner.
Keep firewall maintenance moving
For related active-exploitation work, see the Cisco SD-WAN KEV patch guide and the Cisco SD-WAN privilege-escalation checklist. Teams managing several security platforms can also use the FixItPhill security hub and the hosting security guidance to plan adjacent maintenance.

