Junglewise Threat Intelligence

CVE-2026-20316: Cisco Secure Firewall Management Center static credentials in web interface

CVE-2026-20316 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2026-07-29

Technologies: Cisco Secure Firewall Management Center, Cisco Secure Firewall Management Center Software, Cisco Secure Firewall Management Center (FMC). Vendors: Cisco.

Executive brief

Cisco Secure Firewall Management Center (FMC) is a centralized administrative tool used to manage network security policies and firewall devices. A vulnerability exists where a low-privileged account has a permanent, pre-set password that cannot be changed. An unauthorized person could use these credentials to log into the management interface and view sensitive configuration or system data. While the account has limited permissions, this access could be used as a starting point for more advanced attacks against the network infrastructure.

Technical details

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software (CWE-259) is caused by the presence of static user credentials for a low-privileged account. An unauthenticated, remote attacker can exploit this by logging into the affected system using these hard-coded credentials. While the initial access is limited to low-privileged data, Cisco has elevated the internal Security Impact Rating to High because this access can be chained with other vulnerabilities to achieve privilege escalation. The attack surface is significantly reduced if the FMC management interface is not exposed to the public internet. Patch information is available via the official Cisco security advisory.

Affected products

  • Cisco Secure Firewall Management Center (FMC) 7.0.0 through 7.4.1.1

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

Related threats