ctipilot.ch

CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing

cve · CVE-2026-20316 single-source

Coverage timeline
1
first 2026-07-30 → last 2026-07-30
Peak priority
high
1 high
Sources cited
1
1 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Cisco Secure Firewall Management Center

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-30/cisco-secure-fmc-cve-2026-20316-static-credential-exploited · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-30/cisco-secure-fmc-cve-2026-20316-static-credential-exploited · ATT&CK page ↗

Persistence TA0003

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-30/cisco-secure-fmc-cve-2026-20316-static-credential-exploited · ATT&CK page ↗

Privilege Escalation TA0004

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-30/cisco-secure-fmc-cve-2026-20316-static-credential-exploited · ATT&CK page ↗

Stealth TA0005

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-30/cisco-secure-fmc-cve-2026-20316-static-credential-exploited · ATT&CK page ↗

Story timeline

  1. 2026-07-30CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing
    trending-vulnerabilitiesCisco patches an actively exploited hardcoded credential in Secure FMC — CVSS 5.3, but Cisco rates the advisory High for privilege-escalation chaining

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • sec.cloudapps.cisco.com1 (100%)

explore in graph

Entries about CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing (1)

2026-07-30 · view entry permalink →

HIGHCVE-2026-20316exploitedNATOA2

CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing

Cisco Secure Firewall Management Center is the management plane for a Cisco firewall estate — it holds policy, device inventory, credentials and certificates for every sensor it manages. CVE-2026-20316 places a vendor-embedded static password for a low-privileged account inside that server's web interface: Cisco states the flaw "is due to the presence of static user credentials for a low-privileged account" and that "an attacker could exploit this vulnerability by using the account to log in to an affected system" (Cisco PSIRT, 2026-07-29). Because the credential ships with the software, there is no attacker-side prerequisite beyond reaching the interface: the account exists on every affected release, so an attacker needs a network path and nothing else.

The exploitation status is what moves this out of the routine patch cycle. Cisco PSIRT states that "in July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability" (Cisco PSIRT, 2026-07-29). This entry's CVE metadata also records the flaw as carried in CISA's Known Exploited Vulnerabilities catalogue, which this run verified independently — jurisdiction-agnostic confirmation that the exploitation is real, as distinct from the US federal remediation deadline attached to it, which carries no operational meaning for this readership.

Read the score and the rating together rather than separately. The CVSS 3.1 base score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) because the exposed account is low-privileged and the direct impact is confidentiality-only, but Cisco overrode that judgement in its own advisory: "Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges" (Cisco PSIRT, 2026-07-29). Treating this as a medium-severity information disclosure and scheduling it accordingly is the wrong read — it is a pre-authenticated foothold on a security-management server, and its value to an attacker is as the first link in a chain.

Affected releases are 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, regardless of how the device is configured, and remediation is a per-train hotfix rather than a single upgrade target; Cisco explicitly states no workaround exists (Cisco PSIRT, 2026-07-29). Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense and Security Cloud Control are listed as not affected (Cisco PSIRT, 2026-07-29), so the exposure is specifically the on-premises management centre.

Detection should start from the authentication surface rather than from network anomaly. Because the account is a fixed, vendor-embedded identity and not one an operator ever provisions, any successful web-interface authentication under it is anomalous by construction — there is no legitimate administrative workflow that uses it, so a single such event is a compromise signal rather than something to baseline. Cisco also publishes a forensic self-check for suspected exploitation, pointing operators at a license.tmp file written under the system temporary directory as the artifact to look for in the device's own logs (Cisco PSIRT, 2026-07-29). Hardening beyond the hotfix is reachability: confine the FMC web interface to a dedicated management segment, since the flaw needs nothing more than a network path to it.

Triage: normal FMC logins map to named operator accounts with a provisioning history and an owner. The discriminator here is identity rather than behaviour: an authentication event for the vendor's static low-privileged account, from any source address including an internal one, has no benign explanation, whereas a failed login from an unexpected address is ordinary internet noise on any exposed management interface.

In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system.

Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

If exploitation is suspected, contact the Cisco Technical Assistance Center (TAC) for assistance with recovery options. At a minimum, Cisco recommends that customers rotate all user credentials, keys, and certificates on the Cisco Secure FMC device because active exploitation of this vulnerability has been ongoing.

Cisco PSIRT 2026-07-29
vulnerability30 Jul 04:52Zsingle-sourceOpen finding ↗
Sources: Cisco PSIRT