Cisco FMC Zero-Day CVE-2026-20316 Actively Exploited via Static Credentials

Static credentials shipped inside a firewall manager handed attackers a built-in way in. Cisco has released hot fixes for Secure Firewall Management Center, and the zero-day is already on CISA's exploited-vulnerabilities list.

Share
Flat white line-art of a firewall console opened by a built-in key, on a teal background — the Cisco FMC static-credentials zero-day, CVE-2026-20316.

Key Takeaways

  • Cisco has confirmed that CVE-2026-20316, a static-credentials vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software, is being actively exploited as a zero-day; the flaw stems from a built-in, low-privileged account whose credentials are the same across affected installations, letting a remote attacker who can reach the management interface authenticate and read sensitive data.
  • Cisco has released hot fixes for Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0; the base CVSS score is 5.3 (Medium), but Cisco assigned a High Security Impact Rating because the account can be chained with other FMC flaws to escalate privileges — while cloud-delivered FMC, Firewall Device Manager, Secure Firewall ASA, and Secure Firewall Threat Defense software are listed as not affected.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 29, 2026, putting US federal agencies on a patching deadline and making the fix urgent for everyone else; the specific attackers, the number of exploited environments, and the full extent of any data exposure have not been disclosed, so defenders should apply Cisco's fixes and lock down management-interface exposure rather than wait for those details.

A built-in account no one should have shipped becomes a live zero-day — Cisco's firewall manager is the exposed console, and the flaw is already on CISA's KEV list.

SAN JOSE, CALIFORNIA — Cisco has confirmed that CVE-2026-20316, a static-credentials vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software, is being actively exploited as a zero-day, and has released hot fixes for the affected releases. The flaw comes from a built-in, low-privileged user account whose credentials ship the same on every affected system, allowing a remote, unauthenticated attacker who can reach the management interface to authenticate and read sensitive information — the classic failure of a secret that was never meant to leave the factory.

The disclosure was reported on July 29 and 30, 2026 by The Hacker News and Help Net Security, and Cisco has published a security advisory. This piece stays on the defender side of the story: what Cisco disclosed, which versions are affected, how to verify exposure, and what remains unconfirmed — not how the flaw is being reached in practice.

At a Glance
FieldDetails
CVECVE-2026-20316
Affected productCisco Secure Firewall Management Center (FMC) Software — web interface
Root causeStatic credentials for a built-in, low-privileged account
Affected releasesSecure FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 (hot fixes released)
Not affectedCloud-delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense, Security Cloud Control
CVSS5.3 base (Medium); Cisco rates the Security Impact High — chainable
ExploitationConfirmed active exploitation as a zero-day
CISA KEVAdded July 29, 2026

What Cisco Disclosed

The vulnerability is tracked as CVE-2026-20316 and affects the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, the platform administrators use to configure and monitor Cisco firewalls. According to Cisco's advisory, the root cause is a set of static credentials for a built-in, low-privileged user account — a username and password that are the same across affected installations rather than generated per device. A remote, unauthenticated attacker who can reach the management interface can use those credentials to authenticate and access sensitive information held by the system.

Cisco has assigned the flaw a base CVSS score of 5.3, which places it in the Medium range on the raw scoring scale. Cisco nonetheless rates the Security Impact as High, because the built-in account can reportedly be combined with other FMC weaknesses to elevate privileges — meaning the low-privileged foothold is a starting point rather than the ceiling. The affected releases are Secure FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0, for which Cisco has published hot fixes. Cisco lists cloud-delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense (FTD) Software, and Security Cloud Control as not affected. In keeping with our house rules on a disclosure of this kind, we are not reproducing the exploitation path; the defender-relevant facts are the affected product, the static-credentials root cause, and the fix.

What FMC Operators Should Verify

The first task is inventory: confirm whether any on-premises Secure Firewall Management Center runs one of the affected releases — 7.0, 7.2, 7.4, 7.6, 7.7, or 10.0 — and apply Cisco's hot fix for that train. Because the exposure lives in the network-management plane rather than in the firewall data path, the priority is any FMC whose web interface is reachable from untrusted networks. Restricting management-interface access to a dedicated administrative network or jump host is the standard containment step while fixes are rolled out, and it blunts a whole category of built-in-credential exposure, not just this one.

Operators running the variants Cisco lists as not affected — cloud-delivered FMC, Firewall Device Manager, ASA, or Threat Defense software on their own — do not need to act on this specific CVE, but should still confirm exactly which management model they run before ruling themselves out. Where FMC logging is available, reviewing authentication activity for the built-in account is a reasonable defensive check; because Cisco has not published indicators tied to specific attackers, that review is about establishing a baseline rather than hunting a named signature.

The Static-Credentials Pattern in Vendor-Shipped Appliances

Static or hard-coded credentials in a security appliance are a recurring failure mode, and CVE-2026-20316 fits the pattern squarely: a secret embedded at manufacture, identical across the fleet, that no customer ever chose or could rotate. It is the same class of exposure that turns network gear into a soft target, and it echoes recent CyberSignal coverage of an actively exploited VPN authentication bypass and of a Cisco network-management zero-day exploited before a patch existed. The through-line is that the appliances meant to enforce the security boundary keep becoming the way through it.

For defenders, the practical lesson is that a built-in credential cannot be patched away by an end user — only the vendor can remove it, and until they do, the exposure is architectural. That reframes the near-term job from tightening a configuration to constraining who can reach the interface at all. It also argues for treating the trustworthiness of management planes as a first-class inventory question: which appliances expose an administrative web interface, from where, and to whom.

KEV Status and Cisco Response

CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, 2026, formal acknowledgement that the flaw is being used in the wild. The KEV listing puts US federal civilian agencies on a remediation deadline under Binding Operational Directive 22-01, and it functions as a strong signal to private-sector defenders that this belongs at the front of the queue — the same urgency that accompanied a recent Ivanti EPMM zero-day added to KEV with a fixed deadline.

Cisco's response has been to release hot fixes for each affected release rather than a single consolidated patch, so operators should confirm they have pulled the fix that matches their exact train. Cisco advisories of this type are the authoritative source for fixed-version numbers and any workarounds, and they are updated as the picture develops; where reporting and the advisory differ, the advisory governs.

Open Questions

Several material facts are not established at publication, and we are not filling them in. Cisco and the reporting reviewed have not named the threat actor or actors behind the exploitation, have not quantified how many environments have been reached, and have not detailed the full scope of data that the built-in account can expose in practice. Whether the activity is opportunistic scanning of exposed interfaces or a more targeted campaign is likewise unstated.

What is confirmed is enough to act on: an actively exploited static-credentials flaw in a widely deployed firewall-management platform, a defined list of affected releases, available hot fixes, and a KEV listing. As Cisco updates its advisory and as any indicators or attribution emerge, the operational picture will sharpen — but none of that is a reason to defer the patch or the interface lockdown that the current facts already justify.


The CyberSignal Analysis

The facts above come from Cisco's advisory, CISA's KEV listing, and the reporting cited; what follows is The CyberSignal's editorial reading, not new reported fact.

Signal 01 — A Shipped Secret Is Not a Bug You Can Argue With

The uncomfortable quality of a static-credentials flaw is that there is nothing for the customer to have done differently. The account was present the day the box was racked, identical to every other affected unit, and invisible to the operator running it. Our reading is that this is why the Medium CVSS undersells the problem: the score measures the single low-privileged foothold, not the fact that the foothold was pre-installed and universal.

That is also why Cisco's High Security Impact Rating is the number to trust over the 5.3. A built-in account that can be chained toward higher privilege is a starting block, and the scoring model was never good at pricing starting blocks. Defenders who triage strictly by base CVSS will rank this below where it belongs.

Signal 02 — The Management Plane Is the Attack Surface

The detail we would underline is where the flaw lives: not in the firewall's traffic-handling path but in the web console that manages it. The management plane is often the least-watched part of a security deployment precisely because it is assumed to sit on a trusted network — an assumption that a reachable interface and a shipped credential quietly invalidate.

The durable takeaway is to treat administrative interfaces as their own inventory and their own perimeter. Knowing which appliances expose a management web interface, and from where, pays off across every future advisory of this shape — because the next one will target the same soft, over-trusted surface.

Signal 03 — KEV Turns "Medium" Into a Deadline

Our assessment is that the KEV listing, not the CVSS number, should drive the schedule here. A 5.3 that is being exploited in the wild outranks a theoretical 9.8 that is not, and CISA's catalog exists to make exactly that reordering explicit. For federal agencies it is a directive; for everyone else it is the clearest available signal that the clock has already started.

The organizations that will handle this well are those that route KEV additions straight into their patch queue regardless of base score. Bit by bit, exploited-in-the-wild is becoming the metric that matters, and this disclosure is a clean case for letting it override the raw math.


Sources

TypeSource
PrimaryCisco — Security Advisory for CVE-2026-20316 (Cisco Security Advisories)
PrimaryCISA — Known Exploited Vulnerabilities Catalog
ReportingThe Hacker News — Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
ReportingHelp Net Security — Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
ReportingBleepingComputer — Cisco warns of FMC static credential flaw exploited in zero-day attacks
RelatedThe CyberSignal — Cisco Secure Workload CVE-2026-20223 Site-Admin Flaw
RelatedThe CyberSignal — Cisco Catalyst SD-WAN Manager CVE-2026-20245 Zero-Day Exploited
RelatedThe CyberSignal — Palo Alto GlobalProtect CVE-2026-0257 VPN Auth Bypass Actively Exploited
RelatedThe CyberSignal — Ivanti EPMM CVE-2026-6973 Zero-Day on CISA KEV