CVECVE-2026-20316
CVSS8.9 (High)
Cisco SIR: High
KEV addedJuly 30, 2026
Fed deadlineAugust 1, 2026
Also watchCVE-2026-20079
critical auth bypass
updated same day
What happened
Cisco published its advisory for CVE-2026-20316 on July 29 and added it to CISA KEV on July 30 after confirming active exploitation in the wild during July. The vulnerability is a hardcoded static credential in the Cisco Secure Firewall Management Center web interface. A low-privileged user account exists in every affected FMC deployment with a username and password that are identical across all installations and that cannot be changed through normal administrative means. An unauthenticated remote attacker who knows these credentials, which are now public, can log in to the FMC web interface directly. The initial access is low-privileged, but Cisco explicitly raises the severity because the foothold can be chained with a second FMC vulnerability, CVE-2026-20079, to escalate privileges and execute arbitrary scripts with root access. CVE-2026-20079 was patched in March 2026 but Cisco updated its advisory on July 29 to include the same indicators of compromise as CVE-2026-20316, suggesting both vulnerabilities may be in use together. FMC manages firewall rules, network objects, VPN configurations, device inventories, event logs, and policy workflows across all Cisco Secure Firewall devices in an environment. Even read-only low-privileged access to that platform is operationally significant for an attacker mapping a target network or preparing a follow-on attack. Hotfixes are available for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cloud-Delivered FMC, Firewall Device Manager, Cisco ASA, Secure Firewall Threat Defense, and Security Cloud Control are not affected. The federal deadline has already passed.
Why it matters
FMC is the central nervous system of a Cisco firewall deployment. An attacker with read access to FMC can enumerate every device under management, review firewall rule sets, identify permitted and blocked traffic flows, and map the network topology the firewall defends. That reconnaissance does not leave obvious traces in typical security monitoring and gives an attacker a detailed picture of the environment before attempting any further action. A hardcoded credential that applies identically to every installation is a particularly significant class of flaw because it cannot be remediated by good password hygiene. There is no configuration an administrator could have made that would have prevented it.
Don't miss
This is the third Cisco firewall management flaw to appear on CISA KEV in 2026. The pattern reflects sustained attacker interest in the management plane of network security infrastructure, consistent with what this brief documented for Check Point SmartConsole in Issue 92 and VMware vCenter in Issue 97. In each case the target is not the firewall itself but the system through which the firewall is managed and configured. Access to the management plane is access to every policy decision the security device enforces. Organizations that restrict FMC management access to dedicated administrative networks rather than exposing it to broader corporate or internet-accessible segments significantly reduce the exposure window for this class of flaw.
Potential actions
- Apply the CVE-2026-20316 hotfix for your FMC version immediately. The federal deadline passed August 1 but the exploitation is active and ongoing. Confirm the hotfix version from Cisco's advisory for your specific FMC branch and apply it before anything else this week.
- Also verify CVE-2026-20079 is patched. Cisco updated that advisory simultaneously with CVE-2026-20316 and added shared indicators of compromise, suggesting both may be chained in active attacks. CVE-2026-20079 was patched in March 2026 but any deployment that missed that patch is now exposed to a root escalation path from the static credential foothold.
- Review FMC access logs for authentication events from unexpected IP addresses since July. Cisco has published indicators of compromise for CVE-2026-20316 that should be used to check whether the static credential account was used in your environment before patching. Contact Cisco TAC if exploitation is suspected, as Cisco recommends rotating all credentials, keys, and certificates on affected FMC devices following confirmed exploitation.
The Sip
The same password on every FMC installation, baked into the software, and now public. Access to FMC is access to the ruleset governing every device it manages. The federal deadline passed Friday. Patch it today and check the logs to find out whether anyone used it before you did.