---
schema: 1
kind: vulnerability
title: "CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing"
headline: "Cisco patches an actively exploited hardcoded credential in Secure FMC — CVSS 5.3, but Cisco rates the advisory High for privilege-escalation chaining"
summary: >
  Cisco disclosed CVE-2026-20316 on 2026-07-29: the web interface of Cisco Secure Firewall Management
  Center carries a vendor-embedded static password for a low-privileged account, which an unauthenticated
  remote attacker can use to log in and reach sensitive data on the management server. Cisco PSIRT states
  it became aware of active exploitation in July 2026 and that exploitation has been ongoing, and CISA
  added the CVE to its Known Exploited Vulnerabilities catalog the same day. The base score is only 5.3
  because the account is low-privileged, but Cisco deliberately raised the advisory's Security Impact
  Rating to High because the account can be combined with other Secure FMC flaws to elevate privileges.
  Releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 are affected regardless of configuration, there is no
  workaround, and Cisco tells customers to rotate every credential, key and certificate on the device.
discovered_at: "2026-07-30T04:52:00Z"
event_date: "2026-07-29"
run_id: 2026-07-30T0409Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, actively-exploited, pre-auth, cisa-kev, auth-bypass, default-config, patch-available]
regions: [global]
sectors: [public-sector, energy, telco, finance]
entities: []
techniques: [T1078.001, T1190]
affected_products: ["Cisco Secure Firewall Management Center"]
cves:
  - id: CVE-2026-20316
    cvss: "5.3"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Cisco Secure FMC Software releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, regardless of device configuration. Cisco lists Cloud-Delivered FMC (cdFMC), Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense and Security Cloud Control as not affected."
    fixed: "Per-release-train hotfixes rather than a single upgrade target — for example Hotfix_GB-7.0.9.1-3 on the 7.0 train, Hotfix_AM-7.7.12.1-2 on 7.7 and Hotfix_P-10.0.1.1-2 on 10.0. Cisco states no workaround exists."
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
    publisher: "Cisco PSIRT"
    date: "2026-07-29"
    role: primary
closed_sources: []
evidence:
  - quote: "In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
    publisher: "Cisco PSIRT"
  - quote: "This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system."
    publisher: "Cisco PSIRT"
  - quote: "Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges."
    publisher: "Cisco PSIRT"
  - quote: "If exploitation is suspected, contact the Cisco Technical Assistance Center (TAC) for assistance with recovery options. At a minimum, Cisco recommends that customers rotate all user credentials, keys, and certificates on the Cisco Secure FMC device because active exploitation of this vulnerability has been ongoing."
    publisher: "Cisco PSIRT"
verification: single-source
sourcing_note: >
  Cisco PSIRT is the primary disclosing party for its own product and is the sole cited source here — a
  vendor PSIRT reporting on its own software, not a national-CERT carve-out. The
  CISA Known Exploited Vulnerabilities listing was verified during this run against CISA's catalogue data
  and is recorded in this CVE's status field, but the catalogue root is not a citable per-item URL under
  this pipeline's sourcing policy, so no body claim rests on it — the active-exploitation statement comes
  from Cisco's own advisory, which is the stronger attribution in any case. The remediation deadline
  attached to that listing is a US federal compliance date and is deliberately not treated as an urgency
  signal for this readership. Reliability is A because Cisco PSIRT is the first-party authority for its own
  product; credibility is 2 rather than 1 because the claim rests on that single uncorroborated advisory —
  a reliable source does not by itself lift the credibility number.
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Apply the per-release-train Secure FMC hotfix on every 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 management centre — the fix is a train-specific hotfix rather than a version upgrade, and Cisco states no workaround exists, so restricting reachability is a containment step and not a substitute."
  - "On every FMC whose web interface has been reachable, rotate all user credentials, keys and certificates: Cisco names this as the minimum response precisely because exploitation has been ongoing, and the static account means anything the management server held may already have been read."
migrated_from: null
---

Cisco Secure Firewall Management Center is the management plane for a Cisco firewall estate — it holds policy, device inventory, credentials and certificates for every sensor it manages. CVE-2026-20316 places a vendor-embedded static password for a low-privileged account inside that server's web interface: Cisco states the flaw "is due to the presence of static user credentials for a low-privileged account" and that "an attacker could exploit this vulnerability by using the account to log in to an affected system" ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)). Because the credential ships with the software, there is no attacker-side prerequisite beyond reaching the interface: the account exists on every affected release, so an attacker needs a network path and nothing else.

The exploitation status is what moves this out of the routine patch cycle. Cisco PSIRT states that "in July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability" ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)). This entry's CVE metadata also records the flaw as carried in CISA's Known Exploited Vulnerabilities catalogue, which this run verified independently — jurisdiction-agnostic confirmation that the exploitation is real, as distinct from the US federal remediation deadline attached to it, which carries no operational meaning for this readership.

Read the score and the rating together rather than separately. The CVSS 3.1 base score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) because the exposed account is low-privileged and the direct impact is confidentiality-only, but Cisco overrode that judgement in its own advisory: "Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges" ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)). Treating this as a medium-severity information disclosure and scheduling it accordingly is the wrong read — it is a pre-authenticated foothold on a security-management server, and its value to an attacker is as the first link in a chain.

Affected releases are 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, regardless of how the device is configured, and remediation is a per-train hotfix rather than a single upgrade target; Cisco explicitly states no workaround exists ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)). Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense and Security Cloud Control are listed as not affected ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)), so the exposure is specifically the on-premises management centre.

Detection should start from the authentication surface rather than from network anomaly. Because the account is a fixed, vendor-embedded identity and not one an operator ever provisions, any successful web-interface authentication under it is anomalous by construction — there is no legitimate administrative workflow that uses it, so a single such event is a compromise signal rather than something to baseline. Cisco also publishes a forensic self-check for suspected exploitation, pointing operators at a `license.tmp` file written under the system temporary directory as the artifact to look for in the device's own logs ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)). Hardening beyond the hotfix is reachability: confine the FMC web interface to a dedicated management segment, since the flaw needs nothing more than a network path to it.

**Defender takeaway:** patch on the train, then assume disclosure. Cisco's own minimum guidance is to "rotate all user credentials, keys, and certificates on the Cisco Secure FMC device because active exploitation of this vulnerability has been ongoing" ([Cisco PSIRT, 2026-07-29](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)) — for a box that stores managed-device credentials, that rotation is the remediation, and the hotfix alone only closes the door behind whoever may already have walked through it.

**Triage:** normal FMC logins map to named operator accounts with a provisioning history and an owner. The discriminator here is identity rather than behaviour: an authentication event for the vendor's static low-privileged account, from any source address including an internal one, has no benign explanation, whereas a failed login from an unexpected address is ordinary internet noise on any exposed management interface.
