CVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Exploited in the wild. In CISA KEV since 2026‑07‑29. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the recordWhat it is
From the CVE record
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
In plain language
Written by AI from the recordCVE-2026-20316 is a Cisco Secure Firewall Management Center weakness where attackers can log in using known, fixed login details, so if your web management interface is reachable, you should treat this as an active emergency and take immediate action.
CVE-2026-20316 (CWE-259) is an unauthenticated access issue in Cisco Secure Firewall Management Center (FMC) where known static credentials for a low-privileged account allow remote attackers (no user interaction) to log in and access sensitive data through the web interface; CISA KEV confirms active exploitation.
If you're affected
- Unauthorized access to management data
- Data exposure from the management plane
- Account misuse leading to further compromise
- Operational disruption from incident response
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-07-29.
US federal agencies must remediate by 2026-08-01.
Known use in ransomware campaigns.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
0 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
35% chance of exploitation activity in the next 30 days, which ranks it in the 98th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
- Attention now
Sustained, driven by in-the-wild reports.
Lifecycle
25 events over 58 days, from the signal feeds we watch.
- Analysis publishedCisco's Firewall Manager Just Logged Its Third CISA KEV of 2026. This Time, Three Different Attackers Got There First.
- Patch availablerecord updated
- EPSS band changelow → moderate
- EPSS band change0 → moderateepss band change
- Analysis publishedCVE-2026-20079: the 10.0 auth-bypass that shares a footprint with the FMC bug already under attack
- Analysis publishedThe guardian is the gateway: 2026's exploited-bug list is a map of the security products we trusted
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Scored 5.3 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality LowSome restricted information is disclosed, but limited in scope
- Integrity NoneNo integrity impact
- Availability NoneNo availability impact
Weaknesses
Sources
References in the record
In the news
All news- InfraTrust report warns network management systems under attack
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
- Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
- Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
- We've got one word for it, and it's usually the wrong one
- Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
- Organizations Warned of Cisco Secure FMC Exploitation
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Cisco, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI