CISA Adds Cisco Secure Firewall Flaw to Known Exploited Vulnerabilities Catalog
CISA has added CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of CVE-2026-20316 to its catalog of Known Exploited Vulnerabilities (KEV). This critical flaw resides within Cisco Secure Firewall Management Center and involves the use of a hard-coded password, a common vector for malicious cyber actors.
The inclusion in the KEV catalog signifies that CISA has confirmed active exploitation of this vulnerability in the wild. This designation triggers specific requirements for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive (BOD) 26-04. This directive mandates the prioritization of patching for vulnerabilities listed in the KEV catalog on publicly exposed assets that could lead to full system control post-exploitation.
BOD 26-04 emphasizes a risk-based approach to vulnerability management, urging federal agencies to address high-risk vulnerabilities, such as CVE-2026-20316, with urgency. The directive also outlines expectations for agencies to check for signs of compromise on affected systems prior to applying patches, a crucial step in understanding the full impact of an exploit.
While BOD 26-04 specifically targets FCEB agencies, CISA strongly encourages all organizations, including those in the private sector, to adopt similar risk-based vulnerability management practices. Prioritizing the remediation of vulnerabilities listed in the KEV catalog is a key recommendation for enhancing overall cybersecurity posture.
The hard-coded password vulnerability in Cisco Secure Firewall Management Center presents a significant risk, potentially allowing unauthorized access and control over critical network security infrastructure. The active exploitation observed by CISA underscores the immediate threat posed by this flaw.
CISA continues to actively monitor the threat landscape and will add further vulnerabilities to the KEV catalog as evidence of exploitation emerges. Organizations are advised to regularly consult the KEV catalog and CISA alerts for the latest information on critical vulnerabilities and recommended actions.
CISA also provides a nomination form for the public to submit vulnerabilities that they believe warrant inclusion in the KEV catalog. To be considered, a vulnerability must have a confirmed CVE ID, demonstrable evidence of exploitation, and clear guidance on how to mitigate or patch the issue.
CISA has officially added CVE-2026-20316, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) related to static credentials, to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion confirms that the flaw is being actively exploited in the wild, underscoring the urgency for organizations to apply Cisco's released hot fixes.
The new article provides further technical details on CVE-2026-20316, specifying that the vulnerability stems from static credentials embedded within the Cisco Secure Firewall Management Center (FMC) web interface. It highlights that while the CVSS score is 5.3, Cisco assigned it a High Security Impact Rating due to the potential for privilege escalation when combined with other exploits. The article also details how to check FMC logs for signs of exploitation, such as entries referencing '/var/tmp/license.tmp', and lists the specific FMC Software versions (7.0, 7.2, 7.4, 7.6, 7.7, and 10.0) for which hotfixes have been released.
The vulnerability, CVE-2026-20316, is described as a static credential issue, where default credentials for a low-privilege user account can be leveraged by an attacker to gain unauthorized login access. Cisco has assigned a 'high severity' rating to the flaw, noting it can be chained with other FMC vulnerabilities for privilege escalation. The company became aware of active exploitation in July and has released indicators of compromise to aid detection.
The vulnerability, CVE-2026-20316, is a low-privilege account access flaw that can be chained with other Cisco Secure FMC Software vulnerabilities to achieve higher privileges, leading Cisco to assign it a Security Impact Rating of High. Indicators of compromise include specific log entries related to license files, suggesting potential exploitation on affected devices.
The Cisco Product Security Incident Response Team has confirmed active exploitation of CVE-2026-20316, a static credentials vulnerability in Cisco Secure Firewall Management Center (FMC). While Cisco has provided hotfixes and instructions for detecting indicators of compromise, they strongly recommend rotating all user credentials, keys, and certificates on affected FMC devices due to the ongoing nature of the exploitation.
This new report from Cyber Security News details the specific mechanism of the vulnerability, CVE-2026-20316, highlighting a hard-coded password that allows unauthenticated remote attackers to gain low-privilege access. It further elaborates on the potential impact, including exposure of sensitive network configurations and logs, and reiterates CISA's advice to apply vendor patches or discontinue use if mitigations are unavailable.
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with three new entries. The additions include CVE-2026-20349 affecting Cisco Secure Firewall, CVE-2026-68820 impacting Microsoft Windows, and CVE-2026-72898 for Metabase. This update mandates federal agencies to prioritize patching these actively exploited vulnerabilities on public-facing assets.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20316, an authentication bypass vulnerability affecting Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion indicates that the vulnerability is actively being exploited in the wild, underscoring the urgency for organizations to apply the available patches. The vulnerability, discovered by Andy Niu of TrendAI Research, allows remote attackers to bypass authentication without prior credentials.
This new report details a zero-day vulnerability, CVE-2026-20349, affecting Cisco Secure Firewall ASA and FTD devices, which allows unauthenticated remote attackers to trigger denial-of-service conditions. Unlike the previously reported CVE-2026-20316 which involved hard-coded passwords, this new flaw specifically targets the DoS vector and has also been confirmed to be exploited in the wild, necessitating immediate patching.