THREAT OPS › CVEs › CVE-2026-20316
CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Vulnerability details
- Affected productsSecure Firewall Management Center (FMC)
- KEV remediation due2026-08-01
Related reporting
- Cisco FMC CVE-2026-20079 Actively Exploitedsocradar_blog
- We've got one word for it, and it's usually the wrong onetalos
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiestalos
- ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerabilityzdi_published
- July 2026 CVE Landscaperecordedfuture
- 3rd August – Threat Intelligence Reportcheckpoint_research
- [NVD] CVE-2026-20316 (MEDIUM 5.3) — A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerabilitnvd
- CVE-2026-20316 | Cisco Secure Firewall Management Center Static Credential Vulnerabilityhorizon3
- Cisco security advisory (AV26-757)cccs_ca
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Datathehackernews
- Cisco Secure Firewall Management Center Software Information Disclosure Vulnerabilityhkcert
- Cisco warns of FMC static credential flaw exploited in zero-day attacksbleepingcomputer
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [CISA KEV] CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerabilitycisa_kev
- Cisco Secure Firewall Management Center Software Static Credential Vulnerabilitycisco_psirt