Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2970 articles · 185100 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-20316
cis · secure_firewall_management_center

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Affected Products

VendorProductVersions
cissecure_firewall_management_center7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1, 7.0.3, 7.2.0.1, 7.0.4, 7.2.1, 7.0.5, 7.3.0, 7.2.2, 7.3.1, 7.2.3, 7.2.3.1, 7.2.4, 7.0.6, 7.2.4.1, 7.2.5, 7.3.1.1, 7.4.0, 7.0.6.1, 7.2.5.1, 7.4.1, 7.2.6, 7.4.1.1, 7.0.6.2, 7.2.7, 7.2.5.2, 7.3.1.2, 7.2.8, 7.6.0, 7.4.2, 7.2.8.1, 7.0.6.3, 7.4.2.1, 7.2.9, 7.0.7, 7.7.0, 7.4.2.2, 7.2.10, 7.6.1, 7.4.2.3, 7.0.8, 7.6.2, 7.7.10, 7.2.10.1, 7.0.8.1, 7.6.2.1, 7.2.10.2, 7.7.10.1, 7.4.2.4, 7.4.3, 7.7.11, 7.6.4, 10.0.0, 7.4.4, 7.4.5, 7.0.9, 7.2.11, 7.7.12, 7.6.5, 7.4.6, 10.0.1, 7.4.7

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco secure firewall management centercert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

Related News (11 articles)

Tier D
The Hacker News2d ago
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
→ No new info (linked only)
Tier B
CERT-FR6d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier B
CCCS Canada9d ago
Cisco security advisory (AV26-757)
→ No new info (linked only)
Tier D
Help Net Security9d ago
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
→ No new info (linked only)
Tier B
BSI Advisories9d ago
[NEU] [mittel] Cisco Secure Firewall Management Center: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier D
SecurityWeek9d ago
Cisco Secure FMC Zero-Day Exploited in the Wild
→ No new info (linked only)
Tier D
The Hacker News9d ago
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
→ No new info (linked only)
Tier B
CERT-FR10d ago
Vulnérabilité dans Cisco Firewall Management Center (30 juillet 2026)
→ No new info (linked only)
Tier D
BleepingComputer10d ago
Cisco warns of FMC static credential flaw exploited in zero-day attacks
→ No new info (linked only)
Tier C
VulDB10d ago
CVE-2026-20316 | Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure
→ No new info (linked only)
Tier A
Cisco Security10d ago
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-259
PublishedJul 29, 2026
Last enriched10d ago
Trending Score58
Source articles11
Independent9
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20272
Cisco IOS XE Software Security Hardening Release
Trending: 57
CRITICALCVE-2026-20267
Cisco IOS XE Software Security Hardening Release
Trending: 48
HIGHCVE-2026-20268
Cisco IOS XE Software Security Hardening Release
Trending: 47
HIGHCVE-2026-20269
Cisco IOS XE Software Security Hardening Release
Trending: 37
HIGHCVE-2026-20271
Cisco IOS XE Software Security Hardening Release
Trending: 37

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 29, 2026
Discovered by ZDM
Jul 29, 2026