Cisco Secure Firewall Management Center Static Credential Vulnerability
CVE-2026-20316 is a static credential vulnerability affecting Cisco Secure Firewall Management Center (FMC), Cisco’s centralized management platform for Secure Firewall deployments. The vulnerability allows a remote, unauthenticated attacker to authenticate to the FMC web interface using a hard-coded low-privileged account. Cisco has assigned the vulnerability a CVSS score of 8.9 (High) and confirmed active exploitation in the wild. The vulnerability was discovered by Horizon3.ai’s attack research team and has been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Technical Details
CVE-2026-20316 is a CWE-259: Use of Hard-coded Password vulnerability in the Cisco Secure Firewall Management Center web interface.
The flaw allows a remote, unauthenticated attacker to log in using a built-in static account present on affected systems. While the account provides only low-privileged access, Cisco states that attackers may combine this vulnerability with other Cisco Secure FMC vulnerabilities to elevate privileges and further compromise the management platform.
Cisco assigns the vulnerability a CVSS 8.9 (High) score and a Security Impact Rating (SIR) of High because of the risk posed by chaining this vulnerability with additional flaws.
The following Cisco products are not affected:
- Cloud-Delivered Firewall Management Center (cdFMC)
- Firewall Device Manager (FDM)
- Secure Firewall ASA Software
- Secure Firewall Threat Defense (FTD) Software
- Security Cloud Control (SCC)
Cisco has confirmed active exploitation.
NodeZero® Proactive Security Platform — Rapid Response
A NodeZero Rapid Response test has been developed to safely validate whether this vulnerability can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate evidence of exposure.
- Run the Rapid Response test: Launch the test from the NodeZero platform to determine whether affected Cisco Secure Firewall Management Center instances are vulnerable.
- Patch immediately: Apply the Cisco hot fix for your software release.
- Re-run the test: Confirm the vulnerability is no longer exploitable after remediation.
Indicators of Compromise
Cisco recommends checking affected appliances for evidence of compromise.
| Indicator Type | Description |
| Command | cat /var/log/messages | grep license |
| File | If /var/tmp/license.tmp appears in the output, contact Cisco TAC and rotate all credentials, keys, and certificates stored on the affected FMC appliance. |
Affected Versions & Patch
Affected
- 7.0.0–7.0.9
- 7.2.0–7.2.11
- 7.3.0–7.3.1.2
- 7.4.0–7.4.7
- 7.6.0–7.6.5
- 7.7.0–7.7.12
- 10.0.0–10.0.1
Fixed
Cisco has released hot fixes for each affected software branch through Cisco Software Center.
Mitigations
There are no workarounds. Organizations should immediately install the appropriate hot fix and investigate any indicators of compromise. If compromise is suspected, Cisco recommends rotating all credentials, certificates, and keys managed by the affected FMC appliance.
Timeline
- July 30, 2026: Cisco published its security advisory for CVE-2026-20316 and released hot fixes for affected Cisco Secure Firewall Management Center software.
- July 30, 2026: Cisco confirmed active exploitation of the vulnerability.
- July 30, 2026: CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities (KEV) Catalog with an August 1, 2026 remediation deadline for Federal Civilian Executive Branch agencies.
- July 30, 2026: Horizon3.ai released a NodeZero Rapid Response test.