Skip to content
feed: live
>_ 0dayNews
CVE Record
[ MEDIUM ] CVE-2026-20316

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

cat cve-2026-20316.json
Vendor
Cisco
Product
Cisco Secure Firewall Management Center (FMC)
CVSS
5.3
EPSS (exploit probability)
N/A
Status
kev
Published

Cisco Secure Firewall Management Center (FMC) — the former Firepower Management Center — ships with a hardcoded low-privileged user account in its web interface. An unauthenticated remote attacker with network access to the FMC management interface can log in using this static credential and read sensitive configuration data.

The number says 5.3 (medium). The real risk is higher. Cisco’s own Security Impact Rating for this advisory is High, because CVE-2026-20316 chains with other Cisco Secure FMC vulnerabilities to enable privilege escalation. CISA added it to the Known Exploited Vulnerabilities catalog on July 29, 2026, confirming attackers are actively using it.

Affected: Cisco Secure Firewall Management Center (FMC) Software. If the FMC management interface doesn’t have public internet access, Cisco says the attack surface is reduced — but only reduced, not eliminated.

Action items:

  1. Apply the fix — see cisco-sa-fmc-static-cred-BET3Cjh for affected versions and upgrade paths.
  2. Verify that FMC management interfaces are not internet-accessible.
  3. Review access logs for any authentication events from unknown accounts.
  4. Treat this as a chaining risk: if another unpatched FMC vulnerability is present, the combination is materially more dangerous than either score alone.