Skip to content
CC-4822

CC-4822

Digital.Nhs.Uk [email protected] (NHS Digital) July 30, 2026

Successful exploitation of CVE-2026-20316 could allow an unauthenticated remote attacker to log into an affected device using a low-privileged account and access sensitive information

Successful exploitation of CVE-2026-20316 could allow an unauthenticated remote attacker to log into an affected device using a low-privileged account and access sensitive information

The following platforms are known to be affected:

Cisco Secure Firewall Management Center (FMC)

Note: This vulnerability affects Cisco Secure FMC Software, regardless of device configuration.

Exploitation of CVE-2026-20316

Cisco has confirmed that CVE-2026-20316 has been actively exploited in the wild and the vulnerability has been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog.

The NHS England National CSOC assesses further exploitation as likely.

Cisco has released a security advisory to address a high severity vulnerability in Cisco Secure Firewall Management Center (FMC) Software. Successful exploitation could allow an unauthenticated remote attacker to log into an affected device using a low-privileged account and access sensitive information.

Note : If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

This vulnerability may be chained with other Cisco Secure FMC Software vulnerabilities to achieve privilege escalation; however, Cisco has not disclosed which specific vulnerabilities can be chained with CVE-2026-20316.

Affected organisations are encouraged to review Cisco advisory cisco-sa-fmc-static-cred-BET3Cjh and apply the relevant update as soon as possible.

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Last edited: 30 July 2026 1:53 pm