CVE-2026-20316
Confirmed PUBLISHEDCisco Secure Firewall Management Center Software Static Credential Vulnerability
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
- CVE Published
- Jul 29, 2026
- Exploitation Reported
- Jul 29, 2026
- CVSS
- 5.3 Medium
- EPSS
- —
Affected Versions
67 version rows · page 3 of 3
| Vendor | Product | Version | Status |
|---|---|---|---|
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.6.2.1 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.2.10.2 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.7.10.1 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.4.2.4 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.4.3 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.7.11 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.6.4 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
10.0.0 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.4.4 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.4.5 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.0.9 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.2.11 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.7.12 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.6.5 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.4.6 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
10.0.1 |
Affected |
| Cisco |
Cisco Secure Firewall Management Center (FMC)
|
7.4.7 |
Affected |
CVE References
- cisco-sa-fmc-static-cred-BET3Cjh sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2026-07-29 18:45 UTC |
| CVE | 2026-07-29 19:30 UTC |
| BleepingComputer | 2026-07-29 21:35 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation Status
Exploited in the wild
Recorded 2026-07-29 18:45:59 UTC · CISA
Weaknesses (CWE)
-
Use of Hard-coded Password
Recent Mentions
BleepingComputer · Jul 29, 2026
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
Cisco Security Advisory · Jul 29, 2026
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh Security Impact Rating: High CVE: CVE-2026-20316
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
21:35 UTC about 5 hours ago21:35 UTC · about 5 hours ago
KEV confirmed by BleepingComputer
Exploitation attested by an external source
-
19:30 UTC about 7 hours ago19:30 UTC · about 7 hours ago
KEV confirmed by CVE
Exploitation attested by an external source
-
18:45 UTC about 8 hours ago18:45 UTC · about 8 hours ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
16:22 UTC about 10 hours ago16:22 UTC · about 10 hours ago
CVE published
Vulnerability disclosed publicly
-
11:59 UTC 10 months ago11:59 UTC · 10 months ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2026-20316
{
"cve_id": "CVE-2026-20316",
"title": "Cisco Secure Firewall Management Center Software Static Credential Vulnerability",
"affected_vendor": "Cisco",
"affected_product": "Cisco Secure Firewall Management Center (FMC)",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 5.3,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}