← Vulnerability feed

Vulnerability record · CVE-2026-20316 · published 29 July 2026

CVE-2026-20316: Cisco Secure Firewall Management Center static credentials allow unauthenticated login

Cisco · Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC) Software contains hard-coded credentials for a low-privileged account in its web interface. An unauthenticated remote attacker who can reach the management interface can log in with those static credentials and read sensitive data. Cisco rates the advisory High rather than the CVSS Medium because the access can be chained with other FMC flaws to escalate privileges.

5.3 CVSS 3.1 Medium CISA KEV since 29 Jul 2026 Known ransomware use EPSS 35% · top 1.6% CWE-259 · Hard-coded password
5.3CVSS 3.1 base score
35%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
16 Sep 2026Last modified by NVD

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows unauthenticated remote login with hard-coded credentials, is listed in CISA KEV with known ransomware campaign use, and has a near-term federal remediation deadline.

What it is

Cisco Secure Firewall Management Center (FMC) Software contains hard-coded credentials for a low-privileged account in its web interface. An unauthenticated remote attacker who can reach the management interface can log in with those static credentials and read sensitive data. Cisco rates the advisory High rather than the CVSS Medium because the access can be chained with other FMC flaws to escalate privileges.

Impact

The attacker gains authenticated access as a low-privileged user and can read sensitive data held in the affected system. That foothold can be combined with other FMC vulnerabilities to elevate privileges.

Attack surface

Reachable over the network through the FMC web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Cisco notes the attack surface is reduced if the FMC management interface is not exposed to the public internet.

Exploitation

CVE-2026-20316 was added to CISA KEV on 2026-07-29 with a remediation due date of 2026-08-01 and is flagged for known ransomware campaign use. EPSS gives a 30-day exploitation probability of 0.11153 (95.7th percentile), and the only references are the Cisco advisory and the KEV entry, so no public exploit details are provided in this record.

What to do

  • Apply the fixed FMC software version per the Cisco security advisory cisco-sa-fmc-static-cred-BET3Cjh as the first action.
  • If a patch is not yet available, follow CISA BOD 26-04 guidance for cloud services or discontinue use of the product.
  • Remove or block public internet exposure of the FMC management interface to shrink the attack surface.
  • Rotate or disable the affected low-privileged account and review its access to sensitive data.
  • Treat FMC as a high-value target and prioritize remediation within the CISA KEV due date of 2026-08-01.

Detection

  • Hunt FMC authentication logs for successful logins by the low-privileged static account, especially from unexpected source IPs.
  • Alert on FMC management interface logins originating from the internet or from hosts outside the administrative network.
  • Correlate FMC login events with subsequent privilege-escalation or exploitation attempts against other FMC vulnerabilities.
  • Monitor for the static credential being used across multiple FMC instances, which would indicate automated scanning or exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog on 29 July 2026 as "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 1 August 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20316 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-20131Cisco Secure Firewall Management Center Java deserialization RCECisco Secure Firewall Management Center (FMC) web management interface deserializes a user-supplied Java byte stream without validation, allowing una…KEVEPSS 43%analysed10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed10.0CVE-2025-20265Cisco secure firewall management center injection vulnerabilityA vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remo…EPSS 16%9.9CVE-2024-20424Cisco secure firewall management center os command injection vulnerabilityA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…EPSS 0.94%9.9CVE-2023-20048Cisco secure firewall management center improper privilege management vulnerabilityA vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex…EPSS 16%9.8CVE-2019-16028Cisco secure firewall management center improper authentication vulnerabilityA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to b…EPSS 3.4%9.8CVE-2020-3318Cisco secure firewall management center hard-coded credentials vulnerabilityMultiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to acces…EPSS 0.96%8.8CVE-2024-20360Cisco secure firewall management center sql injection vulnerabilityA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attack…EPSS 0.83%

Source: NIST National Vulnerability Database (record CVE-2026-20316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.