Skip to content
feed: live
>_ 0dayNews
cisco
● Breaking

CISA KEV: Cisco FMC Hard-Coded Password Now Exploited

CISA added CVE-2026-20316 to its KEV catalog. Cisco Secure FMC carries a hardcoded credential—medium CVSS, High by Cisco's own rating, now confirmed exploited.

CISA KEV: Cisco FMC Hard-Coded Password Now Exploited
Photo: ArnoldReinhold / Wikimedia Commons · CC BY-SA 3.0
kilobaud Dave "Kilobaud" Ferris · Published · 1 min read

CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog today, confirming active exploitation of a hardcoded credential in Cisco Secure Firewall Management Center (FMC) — the management console for Cisco Secure Firewall products, formerly Firepower Management Center.

The flaw is exactly what it sounds like: a static, low-privileged user account is baked into FMC’s web interface. An unauthenticated attacker who can reach the management interface can log in using that credential and access sensitive system data.

The score says 5.3. The risk is higher. NVD rates this medium — not wrong for the standalone flaw. Cisco’s own Security Impact Rating for cisco-sa-fmc-static-cred-BET3Cjh is High, because this CVE doesn’t stay standalone. It chains with other Cisco Secure FMC vulnerabilities to enable privilege escalation. A low-privileged account in a firewall management console is the kind of foothold that earns a longer look — CISA’s KEV addition means people are already taking that longer look.

CISA’s July 29 update also references BOD 26-04, which layers forensic triage requirements onto the standard remediation timeline for federal agencies running affected systems.

Cisco notes the attack surface is reduced when the FMC management interface is not publicly internet-accessible. That qualifier shows up in a lot of advisories. It’s worth hearing as a reminder that management plane exposure is its own risk category — but it’s not a reason to hold the patch.

Affected: Cisco Secure Firewall Management Center (FMC) Software. Specific version ranges and upgrade paths are in Cisco’s advisory.

What to do:

  • Apply Cisco’s fix. There is no documented workaround for the underlying credential issue.
  • Confirm FMC management interfaces are not reachable from the public internet — and if they are, address that regardless of this CVE.
  • Review authentication logs for any login events from accounts you didn’t create.
  • If you’re carrying other unpatched Cisco Secure FMC vulnerabilities, this hardcoded credential is the first link in a worse chain. The upgrade matters more than any single score suggests.
Related CVEs
  • [ MEDIUM ] CVE-2026-20316 Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Found this useful? Share it.