CVE Tools

CVE-2026-20316

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Exploited in the wild. In CISA KEV since 2026‑07‑29. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

What it is

From the CVE record

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

In plain language

Written by AI from the record

CVE-2026-20316 is a Cisco Secure Firewall Management Center weakness where attackers can log in using known, fixed login details, so if your web management interface is reachable, you should treat this as an active emergency and take immediate action.

CVE-2026-20316 (CWE-259) is an unauthenticated access issue in Cisco Secure Firewall Management Center (FMC) where known static credentials for a low-privileged account allow remote attackers (no user interaction) to log in and access sensitive data through the web interface; CISA KEV confirms active exploitation.

If you're affected

  • Unauthorized access to management data
  • Data exposure from the management plane
  • Account misuse leading to further compromise
  • Operational disruption from incident response

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS98th
Public exploit
CISA KEV
CISA KEV

Listed as exploited in the wild since 2026-07-29.

US federal agencies must remediate by 2026-08-01.

Known use in ransomware campaigns.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Public exploits

0 sources with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

35% chance of exploitation activity in the next 30 days, which ranks it in the 98th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Sustained, driven by in-the-wild reports.

Lifecycle

25 events over 58 days, from the signal feeds we watch.

  1. Analysis publishedCisco's Firewall Manager Just Logged Its Third CISA KEV of 2026. This Time, Three Different Attackers Got There First.
  2. Patch availablerecord updated
  3. EPSS band changelow → moderate
  4. EPSS band change0 → moderateepss band change
  5. Analysis publishedCVE-2026-20079: the 10.0 auth-bypass that shares a footprint with the FMC bug already under attack
  6. Analysis publishedThe guardian is the gateway: 2026's exploited-bug list is a map of the security products we trusted

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Scored 5.3 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality LowSome restricted information is disclosed, but limited in scope
  • Integrity NoneNo integrity impact
  • Availability NoneNo availability impact

Weaknesses

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Cisco, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store