A static-credential flaw (CVSS 5.3) in Cisco Secure Firewall Management Center lets an unauthenticated remote attacker log in to a low-privileged account and read sensitive data; Cisco PSIRT confirmed active exploitation in July 2026 and CISA added it to the KEV catalog on 2026-07-29 with a 2026-08-01 required-action date.
What Is It
CVE-2026-20316 is a use of hard-coded password vulnerability (CWE-259) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, formerly known as Firepower Management Center.
Per the Cisco advisory, affected releases ship with static credentials for a low-privileged account. An unauthenticated, remote attacker can authenticate to the FMC web interface with those credentials and access sensitive data on the appliance. No user interaction, prior access, or privilege is required.
The CVSS base score of 5.3 reflects only the direct confidentiality impact of that low-privileged login. Cisco assigns the advisory a High Security Impact Rating regardless, because the account obtained through this flaw can be chained with other Cisco Secure FMC vulnerabilities to escalate privileges; the initial foothold is the point, not the endpoint.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, network-reachable, low attack complexity, no privileges, no user interaction, low confidentiality impact only.
Three factors raise the practical urgency well above what a 5.3 suggests:
- Confirmed in-the-wild exploitation. Cisco PSIRT states it became aware of active exploitation of this vulnerability in July 2026. This is not a theoretical credential-hygiene finding.
- The target is the management plane. FMC is the central console for Cisco firewall estates; policy, rules, logs, and device inventory for every managed sensor. A read-only foothold there exposes network topology and security posture across the fleet, and it is the natural staging point for the privilege-escalation chain Cisco describes.
- No workaround exists. Cisco states plainly that there are no workarounds. Patching (or removing exposure) is the only remediation.
CISA's KEV entry lists known ransomware campaign use as Unknown. The required action is due 2026-08-01, a three-day window from the 2026-07-29 catalog addition.
What's Vulnerable
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center
- Affected version ranges (NVD CPE configurations):
- 7.0.0 through 7.0.9
- 7.2.0 through 7.2.11
- 7.3.0 through 7.3.1.2
- 7.4.0 through 7.4.7
- 7.6.0 through 7.6.5
- 7.7.0 through 7.7.12
- 10.0.0 through 10.0.1
- Note on 7.3.x: NVD lists a 7.3 range, but Cisco's advisory enumerates fixed hotfixes only for the 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 trains. Operators on 7.3.x should confirm remediation status directly with Cisco TAC rather than assume either coverage or immunity.
Patch Status
A fix exists. Cisco has released hotfixes for every affected train:
| Train | Fixed hotfix |
|---|---|
| 7.0 | GB-7.0.9.1-3 |
| 7.2 | HL-7.2.11.1-4 |
| 7.4 | HG-7.4.7.1-3 |
| 7.6 | CY-7.6.5.1-2 |
| 7.7 | AM-7.7.12.1-2 |
| 10.0 | P-10.0.1.1-2 |
There are no workarounds, so applying the appropriate hotfix is the only remediation Cisco offers.
CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; for cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Agencies are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Because exploitation is confirmed and the credentials are static, any FMC whose web interface has been internet-reachable on a vulnerable build should be treated as a triage candidate, not merely a patch candidate.
Sources
- Cisco Security Advisory, cisco-sa-fmc-static-cred-BET3Cjh: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- NVD, CVE-2026-20316: https://nvd.nist.gov/vuln/detail/CVE-2026-20316
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- CISA BOD 26-04, Prioritizing Security Updates Based on Risk: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements): https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk