2026-07-30 · view entry permalink →
CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing
Cisco Secure Firewall Management Center is the management plane for a Cisco firewall estate — it holds policy, device inventory, credentials and certificates for every sensor it manages. CVE-2026-20316 places a vendor-embedded static password for a low-privileged account inside that server's web interface: Cisco states the flaw "is due to the presence of static user credentials for a low-privileged account" and that "an attacker could exploit this vulnerability by using the account to log in to an affected system" (Cisco PSIRT, 2026-07-29). Because the credential ships with the software, there is no attacker-side prerequisite beyond reaching the interface: the account exists on every affected release, so an attacker needs a network path and nothing else.
The exploitation status is what moves this out of the routine patch cycle. Cisco PSIRT states that "in July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability" (Cisco PSIRT, 2026-07-29). This entry's CVE metadata also records the flaw as carried in CISA's Known Exploited Vulnerabilities catalogue, which this run verified independently — jurisdiction-agnostic confirmation that the exploitation is real, as distinct from the US federal remediation deadline attached to it, which carries no operational meaning for this readership.
Read the score and the rating together rather than separately. The CVSS 3.1 base score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) because the exposed account is low-privileged and the direct impact is confidentiality-only, but Cisco overrode that judgement in its own advisory: "Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges" (Cisco PSIRT, 2026-07-29). Treating this as a medium-severity information disclosure and scheduling it accordingly is the wrong read — it is a pre-authenticated foothold on a security-management server, and its value to an attacker is as the first link in a chain.
Affected releases are 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, regardless of how the device is configured, and remediation is a per-train hotfix rather than a single upgrade target; Cisco explicitly states no workaround exists (Cisco PSIRT, 2026-07-29). Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense and Security Cloud Control are listed as not affected (Cisco PSIRT, 2026-07-29), so the exposure is specifically the on-premises management centre.
Detection should start from the authentication surface rather than from network anomaly. Because the account is a fixed, vendor-embedded identity and not one an operator ever provisions, any successful web-interface authentication under it is anomalous by construction — there is no legitimate administrative workflow that uses it, so a single such event is a compromise signal rather than something to baseline. Cisco also publishes a forensic self-check for suspected exploitation, pointing operators at a license.tmp file written under the system temporary directory as the artifact to look for in the device's own logs (Cisco PSIRT, 2026-07-29). Hardening beyond the hotfix is reachability: confine the FMC web interface to a dedicated management segment, since the flaw needs nothing more than a network path to it.
Triage: normal FMC logins map to named operator accounts with a provisioning history and an owner. The discriminator here is identity rather than behaviour: an authentication event for the vendor's static low-privileged account, from any source address including an internal one, has no benign explanation, whereas a failed login from an unexpected address is ordinary internet noise on any exposed management interface.
In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system.
Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
If exploitation is suspected, contact the Cisco Technical Assistance Center (TAC) for assistance with recovery options. At a minimum, Cisco recommends that customers rotate all user credentials, keys, and certificates on the Cisco Secure FMC device because active exploitation of this vulnerability has been ongoing.