Robotics & Physical AIJul 30, 2026
Patch now: a hard-coded password in Cisco’s firewall manager, with a three-day federal deadline
CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalogue on 29 July 2026: a hard-coded password in Cisco Secure Firewall Management Center that lets an unauthenticated remote attacker log in with a low-privileged account and reach sensitive data, with federal remediation due 1 August. Two days earlier the catalogue took an OS command-injection flaw in Arista’s on-prem VeloCloud Orchestrator (CVE-2026-16812, due 30 July) and a patch-bypass information disclosure in Fortinet FortiOS reachable by crafted HTTP request (CVE-2025-68686, due 10 August). Catalogue version 2026.07.29; ransomware use is listed as unknown for all three.
What it means Three network-edge devices, one of them the box that manages your firewall rules — and the shortest due date CISA has set this month.
Where it came from CISA