Vulnerability record · CVE-2026-20316 · published 29 July 2026
CVE-2026-20316: Cisco Secure Firewall Management Center static credentials allow unauthenticated login
Cisco · Secure Firewall Management Center
Cisco Secure Firewall Management Center (FMC) Software contains hard-coded credentials for a low-privileged account in its web interface. An unauthenticated remote attacker who can reach the management interface can log in with those static credentials and read sensitive data. Cisco rates the advisory High rather than the CVSS Medium because the access can be chained with other FMC flaws to escalate privileges.
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
critical priorityThe flaw allows unauthenticated remote login with hard-coded credentials, is listed in CISA KEV with known ransomware campaign use, and has a near-term federal remediation deadline.
What it is
Cisco Secure Firewall Management Center (FMC) Software contains hard-coded credentials for a low-privileged account in its web interface. An unauthenticated remote attacker who can reach the management interface can log in with those static credentials and read sensitive data. Cisco rates the advisory High rather than the CVSS Medium because the access can be chained with other FMC flaws to escalate privileges.
Impact
The attacker gains authenticated access as a low-privileged user and can read sensitive data held in the affected system. That foothold can be combined with other FMC vulnerabilities to elevate privileges.
Attack surface
Reachable over the network through the FMC web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Cisco notes the attack surface is reduced if the FMC management interface is not exposed to the public internet.
Exploitation
CVE-2026-20316 was added to CISA KEV on 2026-07-29 with a remediation due date of 2026-08-01 and is flagged for known ransomware campaign use. EPSS gives a 30-day exploitation probability of 0.11153 (95.7th percentile), and the only references are the Cisco advisory and the KEV entry, so no public exploit details are provided in this record.
What to do
- Apply the fixed FMC software version per the Cisco security advisory cisco-sa-fmc-static-cred-BET3Cjh as the first action.
- If a patch is not yet available, follow CISA BOD 26-04 guidance for cloud services or discontinue use of the product.
- Remove or block public internet exposure of the FMC management interface to shrink the attack surface.
- Rotate or disable the affected low-privileged account and review its access to sensitive data.
- Treat FMC as a high-value target and prioritize remediation within the CISA KEV due date of 2026-08-01.
Detection
- Hunt FMC authentication logs for successful logins by the low-privileged static account, especially from unexpected source IPs.
- Alert on FMC management interface logins originating from the internet or from hosts outside the administrative network.
- Correlate FMC login events with subsequent privilege-escalation or exploitation attempts against other FMC vulnerabilities.
- Monitor for the static credential being used across multiple FMC instances, which would indicate automated scanning or exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog on 29 July 2026 as "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 1 August 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316 | US Government Resource |
Track CVE-2026-20316 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-20316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.