CVE-2026-20316
Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*range: >=7.0.0,<=7.0.9
Patches
Vulnerability mechanics
References
2- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3CjhnvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
20- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwareThe Hacker News · Sep 11, 2026
- Cisco Firewall Bugs Let in Sandworm, QilinGovInfoSecurity · Sep 10, 2026
- We've got one word for it, and it's usually the wrong oneCisco Talos Intelligence · Sep 10, 2026
- Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy MalwareCyber Security News · Sep 10, 2026
- Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)Help Net Security · Sep 10, 2026
- Organizations Warned of Cisco Secure FMC ExploitationSecurityWeek · Sep 10, 2026
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiesCisco Talos Intelligence · Sep 9, 2026
- ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass VulnerabilityZero Day Initiative · Aug 11, 2026
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score BugsThe Hacker News · Aug 6, 2026
- 3rd August – Threat Intelligence ReportCheck Point Research · Aug 3, 2026
- Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 StoriesCyber Security News · Aug 2, 2026
- Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC releasedHelp Net Security · Aug 2, 2026
- CISA Warns of Cisco Secure Firewall Management 0-Day Vulnerability Exploited in AttacksCyber Security News · Jul 30, 2026
- Cisco FMC static credentials exploited by attackers (CVE-2026-20316)Help Net Security · Jul 30, 2026
- Cisco Secure FMC Zero-Day Exploited in the WildSecurityWeek · Jul 30, 2026
- Cisco Firewall Management Center 0-Day Actively Exploited to Access Sensitive DataCyber Security News · Jul 30, 2026
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe Hacker News · Jul 30, 2026
- Cisco warns of FMC static credential flaw exploited in zero-day attacksBleepingComputer · Jul 29, 2026
- Cisco Secure Firewall Management Center Software Static Credential Vulnerability Added to CISA KEV Under Active ExploitationVypr Intelligence · Jul 29, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts