SYS::ONLINE
Wasteland.
Briefs1600
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-20316 2026-07-29

Cisco Secure Firewall Management Center Hard-Coded Password Flaw Lands in CISA KEV

"A static-credential flaw (CVSS 5.3) in Cisco Secure Firewall Management Center lets an unauthenticated remote attacker log in to a low-privileged account and read sensitive data; Cisco PSIRT confirmed active…"

A static-credential flaw (CVSS 5.3) in Cisco Secure Firewall Management Center lets an unauthenticated remote attacker log in to a low-privileged account and read sensitive data; Cisco PSIRT confirmed active exploitation in July 2026 and CISA added it to the KEV catalog on 2026-07-29 with a 2026-08-01 required-action date.

What Is It

CVE-2026-20316 is a use of hard-coded password vulnerability (CWE-259) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, formerly known as Firepower Management Center.

Per the Cisco advisory, affected releases ship with static credentials for a low-privileged account. An unauthenticated, remote attacker can authenticate to the FMC web interface with those credentials and access sensitive data on the appliance. No user interaction, prior access, or privilege is required.

The CVSS base score of 5.3 reflects only the direct confidentiality impact of that low-privileged login. Cisco assigns the advisory a High Security Impact Rating regardless, because the account obtained through this flaw can be chained with other Cisco Secure FMC vulnerabilities to escalate privileges; the initial foothold is the point, not the endpoint.

Why It Matters

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, network-reachable, low attack complexity, no privileges, no user interaction, low confidentiality impact only.

Three factors raise the practical urgency well above what a 5.3 suggests:

CISA's KEV entry lists known ransomware campaign use as Unknown. The required action is due 2026-08-01, a three-day window from the 2026-07-29 catalog addition.

What's Vulnerable

Patch Status

A fix exists. Cisco has released hotfixes for every affected train:

Train Fixed hotfix
7.0 GB-7.0.9.1-3
7.2 HL-7.2.11.1-4
7.4 HG-7.4.7.1-3
7.6 CY-7.6.5.1-2
7.7 AM-7.7.12.1-2
10.0 P-10.0.1.1-2

There are no workarounds, so applying the appropriate hotfix is the only remediation Cisco offers.

CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; for cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Agencies are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Because exploitation is confirmed and the credentials are static, any FMC whose web interface has been internet-reachable on a vulnerable build should be treated as a triage candidate, not merely a patch candidate.

Sources