CVE-2026-20316
published 2026-07-29CVE-2026-20316: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an…
PriorityP180medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-08-01
Exploited in the wild
EPSS
9.82%
95.2th percentile
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
| cisco | cisco_secure_firewall_management_center | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vulncheck5.3MEDIUM
cisa5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure (EUVD-2026-50404)
vuldb·2026-07-29·CVSS 5.3
CVE-2026-20316 [MEDIUM] Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure (EUVD-2026-50404)
A vulnerability was found in Cisco Secure Firewall Management Center. It has been classified as problematic. Affected is an unknown function of the component Web Interface. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-20316. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
GHSA
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac
ghsa_unreviewed·2026-07-29
CVE-2026-20316 [MEDIUM] CWE-259 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Cisco has assigned this security advisory a Security Impac
VulnCheck
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
vulncheck·2026·CVSS 5.3
CVE-2026-20316 [MEDIUM] CWE-259 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Affected: Cisco Secure Firewall Management Center (FMC)
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if m
CISA
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
cisa·2026-07-29·CVSS 5.3
CVE-2026-20316 [MEDIUM] CWE-259 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Vulnerability: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Affected: Cisco Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of th
No detection rules found.
No public exploits indexed.
Hackernews
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
blogs_hackernews·2026-08-06·CVSS 9.0
CVE-2026-20303 [CRITICAL] Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.
The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.
"These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urgi
Checkpoint
3rd August – Threat Intelligence Report
blogs_checkpoint·2026-08-03
CVE-2026-59726 3rd August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federa
Hackernews
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
blogs_hackernews·2026-07-30·CVSS 5.3
CVE-2026-20316 [MEDIUM] Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of zero-day exploitation.
The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems.
"This vulnerability is due to the pres
2026-07-29
Published
2026-07-29
Added to CISA KEV
Exploited in the wild