Cisco FMC Static Credential Vulnerability Under Active Exploitation

Cisco FMC Static Credential Vulnerability Under Active Exploitation

First seen 30 Jul 2026, 08:20 UTC BleepingcomputerCybersecuritynewsHeise.DeFeeds.4SysopsFeeds2.Feedburner+3 87% similarity 72.0

Article Content

Browse articles
ThreatCluster

Cisco has reported a high-severity vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC) software, which is being actively exploited in the wild. The flaw arises from hardcoded static credentials for a low-privileged account, allowing unauthenticated remote attackers to log in and access sensitive data. Despite a CVSS score of 5.3, Cisco has assigned a High severity rating due to the potential for privilege escalation when combined with other vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog. Cisco has released hotfixes for several affected software versions, urging immediate installation. The vulnerability affects all configurations of Cisco Secure FMC Software but does not impact Cloud-Delivered FMC or other firewall software. Administrators are advised to check logs for indicators of compromise and to contact Cisco's Technical Assistance Center for recovery assistance. The vulnerability was first disclosed on July 29, 2026.

Key Points: • CVE-2026-20316 allows unauthenticated access to sensitive data via hardcoded credentials. • Cisco has released hotfixes for affected FMC software versions; immediate patching is advised. • CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-03-04
CVE-2026-20079 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-29
CVE-2026-20316 published
Cisco disclosed a vulnerability in Secure Firewall Management Center due to static credentials, enabling unauthorized access.
Bleepingcomputer
2026-07-29
CVE-2026-20316 added to CISA KEV catalog
CISA confirmed that CVE-2026-20316 is actively exploited, prompting its addition to the Known Exploited Vulnerabilities catalog.
Digital.Nhs.Uk
2026-07-30
Cisco releases hotfixes
Cisco issued hotfixes for multiple versions of Secure FMC software to address the vulnerability and mitigate risks.
Heise.De
2026-07-30
Indicators of Compromise shared
Cisco provided specific indicators of compromise for administrators to check for signs of exploitation in their systems.
Feeds.4Sysops

Community

Browse all →