The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in Cisco's Secure Firewall Management Center (FMC) to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild and issuing a remediation directive for federal agencies.

The KEV listing serves as the definitive signal that the vulnerability is being operationally used by threat actors, overriding traditional severity metrics for prioritization purposes. Federal civilian executive branch agencies must now apply Cisco-supplied patches by the deadline CISA establishes.

The Cisco FMC is a high-value target because it functions as the centralized command console for configuring and monitoring fleets of Cisco firewalls. A successful compromise grants attackers the ability to reconfigure security policies, disable protections, or gather intelligence on network defenses, making flaws in such management planes critically dangerous regardless of any base severity rating.

For private-sector organizations, the KEV designation is a clear mandate for action. Security and IT leaders should immediately inventory all FMC deployments to identify vulnerable versions and apply the updates provided in Cisco's official security advisory. Treating the federal patching deadline as a de facto benchmark for internal timelines is a prudent risk management step.

This incident highlights a persistent gap in enterprise defense: management and control-plane systems often lag behind perimeter devices in patch priority. Strengthening vulnerability management to include administrative consoles is essential. As a concurrent hardening measure, organizations should verify that FMC instances are not exposed to untrusted networks and enforce strict access controls, including multi-factor authentication and robust network segmentation.

The inclusion in the KEV catalog removes any ambiguity about the threat. Defenders awaiting higher severity scores or widespread public exploit code are already behind adversaries who are actively exploiting the flaw. Regular, rapid response to KEV alerts for critical infrastructure management tools remains one of the most effective defensive controls available. Organizations should consult Cisco's advisory for precise remediation steps and monitor CISA for the official federal deadline.


美國網絡安全和基礎設施安全局(CISA)已將Cisco安全防火牆管理中心(FMC)的一個漏洞加入其已知遭利用漏洞(KEV)目錄,證實該漏洞已在野外遭積極利用,並向聯邦機構發出修復指令。

將其列入KEV目錄明確表明,威脅行為者已在實際操作中利用此漏洞,這超越了傳統的嚴重性評分,成為優先處理的依據。聯邦民事行政機構現必須在CISA規定的最後期限前,應用Cisco提供的補丁。

Cisco FMC是高價值攻擊目標,因為它作為集中式指令控制台,用於配置和監控大量Cisco防火牆。攻擊者若成功入侵,可重新配置安全策略、禁用防護措施或收集網絡防禦情報,因此此類管理平面的漏洞極為危險,無論其基礎嚴重性評分如何。

對私營機構而言,KEV標記明確要求採取行動。安全和IT主管應立即盤點所有FMC部署,識別受影響版本,並應用Cisco官方安全公告中提供的更新。將聯邦補丁期限視為內部時間表的實際基準,是審慎的風險管理步驟。

此事件突顯了企業防禦的持續缺口:管理和控制平面系統的補丁優先級常落後於邊界設備。加強漏洞管理以涵蓋管理控制台至關重要。作為同步的強化措施,機構應確保FMC實例未暴露於不受信任的網絡,並實施嚴格的訪問控制,包括多重身份驗證和強大的網絡分段。

將其列入KEV目錄消除了對威脅的任何模糊性。防守者若等待更高的嚴重性評分或廣泛公開的漏洞利用代碼,已落後於正在積極利用此漏洞的對手。針對關鍵基礎設施管理工具,定期、快速回應KEV警報仍是現有最有效的防禦控制措施之一。機構應查閱Cisco公告以獲取具體修復步驟,並關注CISA的官方聯邦期限。

新聞來源 / Original News Source