CVE-2026-20316
Published Jul 29, 2026
Last updated a month ago
AI description
CVE-2026-20316 describes a vulnerability found in the web interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw stems from the inclusion of static user credentials for a low-privileged account within the system. An unauthenticated, remote attacker can exploit this vulnerability by utilizing these static credentials to log into an affected device. Successful exploitation grants the attacker access to sensitive data accessible by the low-privileged user account. While the vulnerability provides low-level access, it can potentially be combined with other Cisco Secure FMC Software vulnerabilities to achieve elevated privileges. The attack surface for this vulnerability is reduced if the FMC management interface lacks public internet access. This vulnerability has been actively exploited in zero-day attacks.
- Description
- A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
- Source
- psirt@cisco.com
- NVD status
- Analyzed
- Products
- secure_firewall_management_center
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Exploit added on
- Jul 29, 2026
- Exploit action due
- Aug 1, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@cisco.com
- CWE-259
- Hype score
- Not currently trending
News: Cisco FMC CVE-2026-20079 and CVE-2026-20316 are under live exploit by nation-state and Qilin ransomware crews for root and domain access. Apply Cisco hotfixes now; hunt /var/tmp/license.tmp and rogue tunnels.
@snakeyesV1
12 Sept 2026
104 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 GitLab's CVE-2026-85706 (CVSS 10.0) unauth path traversal was actively exploited within hours of disclosure. Cisco confirms Russia's Sandworm exploiting CVE-2026-20079 + CVE-2026-20316 on Secure FMC for root access. Patch both now. #infosec #CVE #KEV
@ita_ipo
12 Sept 2026
87 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco Talos: three clusters (incl. Qilin + Sandworm-linked) exploiting Secure FMC CVE-2026-20079 / CVE-2026-20316 — webshells, tunnels, credential theft, ransomware. Patch FMC management interfaces; assume exposure if unpatched. https://t.co/QCPV3cYtTg
@richtechguy
11 Sept 2026
109 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Cisco FMC : le 9 sept., Talos a confirmé l’exploitation active de CVE-2026-20079 (CVSS 10) et CVE-2026-20316 par 3 groupes, dont un cluster aux outils proches de Sandworm et un opérateur Qilin. Appliquez les hotfixes immédiatement. #Cyber #Ransomware
@TwitGri
11 Sept 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Talos just mapped three clusters on Cisco FMC: Tomcat web-shell + cred theft, Sandworm-style reverse shell / Cyclops Blink, and Qilin ransomware. Same two bugs — CVE-2026-20079 (unauth auth-bypass to root via crafted HTTP) and CVE-2026-20316 (static low-priv creds). CISA clock
@Chris_L_Elliott
11 Sept 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) - Help Net Security https://t.co/YniPCrhRZk
@PVynckier
11 Sept 2026
221 Impressions
3 Retweets
7 Likes
0 Bookmarks
2 Replies
1 Quote
Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 | Codebook|Security News https://t.co/uwfFixtqRC
@ohhara_shiojiri
11 Sept 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 ⚠️数百体のAIエージェント使った攻撃でPaperCutの脆弱性が悪用され、395超の組織が侵害される:CVE-2026-81
@MachinaRecord
11 Sept 2026
139 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Cisco Talos: two FMC flaws actively exploited by Qilin ransomware and Sandworm-linked hackers. CVE-2026-20079 allows auth bypass & root RCE; CVE-2026-20316 leaks static creds. Patch now. #Cisco #ThreatIntel #CyberSecurity https://t.co/g7vdkGvQ3k
@CyberWorldOps
10 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco FMC bugs CVE-2026-20079 and CVE-2026-20316 are being exploited by nation-state and ransomware actors for unauthenticated access and root control. Talos links activity to Sandworm and Qilin. #CiscoFMC #Sandworm #Qilin https://t.co/BLVRVf8zOs
@TweetThreatNews
10 Sept 2026
196 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) https://t.co/wMUCb8byAe
@TheCyberSecHub
10 Sept 2026
1515 Impressions
0 Retweets
3 Likes
3 Bookmarks
0 Replies
0 Quotes
Sandworm-linked UAT-11823 uses Cisco FMC CVE-2026-20079 and CVE-2026-20316 to drop Cyclops Blink via Netcat reverse shell. IOCs (3): db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e +2 more Full set: https://t.co/DbfSb60b6i
@threatcluster
10 Sept 2026
82 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco FMC(Secure Firewall Management Center)の脆弱性、国家支援型攻撃者とランサムウェア攻撃者が悪用(CVE-2026-20079、CVE-2026-20316) https://t.co/YS5dc4RUO1
@TYOBlackHatNews
10 Sept 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316): State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure… https://t.co/ukmK92j8ZZ h
@shah_sheikh
10 Sept 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
On Sept. 9, 2026, Cisco confirmed exploitation of FMC flaw CVE-2026-20079, which enables unauthenticated root access. Talos also reported attacks using static-credential flaw CVE-2026-20316; not every incident uses both.
@Securehup
10 Sept 2026
28 Impressions
1 Retweet
3 Likes
0 Bookmarks
1 Reply
0 Quotes
Critical zero-days in N-able (CVE-2026-18577) & Cisco FMC (CVE-2026-20316) are under active exploitation, risking network integrity. A QUIC TLS bypass (CVE-2026-49457) also enables MiTM, compromising data privacy in transit. #Cybersecurity #ZeroDay #Infosec
@YourAnon_irc
10 Aug 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco Secure FMC zero day CVE-2026-20316 is under active exploitation. Chained with CVE-2026-20079 (CVSS 10.0 auth bypass), attackers hit root. CISA set FCEB deadline Aug 1. Still unpatched? Assume compromise. #ZeroDay #InfoSec #Cybersecurity
@infrasecserv
9 Aug 2026
96 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Cisco Secure Firewall Management Center = CVSS 10.0 open door. CVE-2026-20079 lets an unauth attacker send a crafted HTTP request → execute scripts → root. CVE-2026-20316 is actively exploited (static creds). Patch this weekend. No workaround. https://t.co/aiO0JUThmq
@FaultSignal_
7 Aug 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New zero-days & CVEs threaten data in transit. Langflow RCE (CVE-2026-9198), SonicWall bypass (CVE-2026-15409), & Cisco FMC static creds (CVE-2026-20316) enable RCE/access, compromising privacy & integrity. Urgent patching vital. #Cybersecurity #ZeroDay #News
@YourAnon_irc
5 Aug 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added Cisco FMC zero-day CVE-2026-20316 to KEV, actively exploited via hard-coded creds. Chainable with CVE-2026-20079 (CVSS 10.0) for root RCE. FCEB deadline was Aug 1. If you run Firepower Mgmt Center, patch now or assume breach. #Cybersecurity #ZeroDay #CVE
@infrasecserv
5 Aug 2026
89 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco Secure FMC CVE-2026-20316 (static creds) + CVE-2026-20079 (CVSS 10.0, auth bypass to root) is a chained zero-day now on CISA KEV. Federal Aug 1 deadline is up. If you own FMC and have not patched, treat as compromised. #Cybersecurity #InfoSec #ZeroDay
@infrasecserv
3 Aug 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco Secure FMC ships with a hardcoded low-priv account (CVE-2026-20316), already exploited. Same advisory reactivates a CVSS 10.0 root bypass (CVE-2026-20079), sharing an IOC. CISA deadline Aug 1. Patch now. https://t.co/6C6UrTKygC https://t.co/tMY18VWLNi #CyberSecurity htt
@DIESEC_GmbH
3 Aug 2026
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-20316: Cisco FMC Actively Exploited — Detection and Hardening Guide "As of July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a…" 🔗 https://t.co/3wxY2xoMSC #CyberSecurity #ThreatIntel #critical #zeroday #c
@SecurityAr58409
1 Aug 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New critical flaws in OliveTin & a Cisco FMC zero-day are impacting backend & network security (CVE-2026-67438, CVE-2026-67437, CVE-2026-20316). These pose significant risks to data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities
@YourAnon_irc
31 Jul 2026
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco FMC has a backdoor credential hard-coded into every version 7.0-10.0. CVE-2026-20316 chains with CVE-2026-20079 (CVSS 10.0) for root shell on your firewall manager. CISA KEV. Patch by August 1. https://t.co/2KicMADqIu #CiscoFMC #ZeroDay
@DecryptionDigst
31 Jul 2026
68 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Cisco FMCの静的認証情報が攻撃者によって悪用される脆弱性(CVE-2026-20316) Cisco FMC static credentials exploited by attackers (CVE-2026-20316) #HelpNetSecurity (Jul 30) https://t.co/xMz7EodYYo
@foxbook
31 Jul 2026
218 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco Secure FMC Static Credential Vulnerability (CVE-2026-20316) — Cisco has disclosed a static credential vulnerability (CVE-2026-20316)… https://t.co/KdhZYC95qB #Cybersecurity #SecOps #VulnerabilityManagement
@VettedSecOps
30 Jul 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco alerta para falhas zero-day no Secure FMC (CVE-2026-20316 e CVE-2026-20079) https://t.co/pJgdXvOkYT
@SempreUpdate
30 Jul 2026
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability Critical Vulnerability Alert! Cisco Firepower Management Center is affected by CVE-2026-20316. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/0Wwteb2wm
@zoomeye_team
30 Jul 2026
1319 Impressions
5 Retweets
18 Likes
7 Bookmarks
0 Replies
0 Quotes
CISA added Cisco FMC CVE-2026-20316 to its KEV catalog after zero-day exploitation reports. Static credentials in a low-privilege account may expose sensitive data and could chain with CVE-2026-20079 for privilege escalation. #Cisco #CISAKev #ZeroDay https://t.co/4IeAMkBcNW
@TweetThreatNews
30 Jul 2026
131 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco warns that CVE-2026-20316 in Secure Firewall Management Center used static credentials, enabling zero-day access to vulnerable devices. Cisco also patched CVE-2026-20079, a critical FMC auth bypass. #Cisco #CVE-2026-20316 #CVE-2026-20079 https://t.co/CxQ53TRfHf
@TweetThreatNews
30 Jul 2026
234 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-20316 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affecte… https://t.co/zoRVIu1vsU ----- Traducción: CVE-2026-20316 Una… https://t.co/utmtNg
@infoflowcloud
29 Jul 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DFD0173-E045-4EF0-BC97-45BBFCFA1502",
"versionEndIncluding": "7.0.9",
"versionStartIncluding": "7.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9DBBB745-D7D2-4E11-ACC7-CE880B066D1E",
"versionEndIncluding": "7.2.11",
"versionStartIncluding": "7.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5CA67B3C-60F2-4373-81B6-FCA063518CB1",
"versionEndIncluding": "7.3.1.2",
"versionStartIncluding": "7.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CD49AB20-6E0A-4C1A-A775-D2EEA55D45D8",
"versionEndIncluding": "7.4.7",
"versionStartIncluding": "7.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9340872F-6A25-467A-BC63-957E1B7E817D",
"versionEndIncluding": "7.6.5",
"versionStartIncluding": "7.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BF37EF84-93E8-4D2F-BFEF-7754B74D1E3F",
"versionEndIncluding": "7.7.12",
"versionStartIncluding": "7.7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7A5384FA-2700-4284-8AAD-27B8923732F3",
"versionEndIncluding": "10.0.1",
"versionStartIncluding": "10.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]