Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-20316
cis · secure_firewall_management_center

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Affected Products

VendorProductVersions
cissecure_firewall_management_center7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1, 7.0.3, 7.2.0.1, 7.0.4, 7.2.1, 7.0.5, 7.3.0, 7.2.2, 7.3.1, 7.2.3, 7.2.3.1, 7.2.4, 7.0.6, 7.2.4.1, 7.2.5, 7.3.1.1, 7.4.0, 7.0.6.1, 7.2.5.1, 7.4.1, 7.2.6, 7.4.1.1, 7.0.6.2, 7.2.7, 7.2.5.2, 7.3.1.2, 7.2.8, 7.6.0, 7.4.2, 7.2.8.1, 7.0.6.3, 7.4.2.1, 7.2.9, 7.0.7, 7.7.0, 7.4.2.2, 7.2.10, 7.6.1, 7.4.2.3, 7.0.8, 7.6.2, 7.7.10, 7.2.10.1, 7.0.8.1, 7.6.2.1, 7.2.10.2, 7.7.10.1, 7.4.2.4, 7.4.3, 7.6.3, 7.7.11, 7.6.4, 10.0.0, 7.4.4, 7.4.5, 7.0.9, 7.2.11, 7.7.12, 7.6.5, 7.4.6, 10.0.1, 7.4.7

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco secure firewall management centercert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

Related News (20 articles)

Tier D
BleepingComputer4d ago
InfraTrust report warns network management systems under attack
→ No new info (linked only)
Tier D
SecurityWeek10d ago
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
→ No new info (linked only)
Tier D
Dark Reading13d ago
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
→ No new info (linked only)
Tier C
Cisco Talos17d ago
We've got one word for it, and it's usually the wrong one
→ No new info (linked only)
Tier D
BleepingComputer17d ago
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
→ No new info (linked only)
Tier D
Help Net Security17d ago
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
→ No new info (linked only)
Tier D
SecurityWeek17d ago
Organizations Warned of Cisco Secure FMC Exploitation
→ No new info (linked only)
Tier E
Reddit r/cybersecurity18d ago
Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild
→ No new info (linked only)
Tier D
BleepingComputer18d ago
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News52d ago
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
→ No new info (linked only)
Tier B
CERT-FR56d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier B
CCCS Canada59d ago
Cisco security advisory (AV26-757)
→ No new info (linked only)
Tier D
Help Net Security59d ago
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
→ No new info (linked only)
Tier B
BSI Advisories59d ago
[NEU] [mittel] Cisco Secure Firewall Management Center: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier D
SecurityWeek59d ago
Cisco Secure FMC Zero-Day Exploited in the Wild
→ No new info (linked only)
Tier D
The Hacker News59d ago
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
→ No new info (linked only)
Tier B
CERT-FR60d ago
Vulnérabilité dans Cisco Firewall Management Center (30 juillet 2026)
→ No new info (linked only)
Tier D
BleepingComputer60d ago
Cisco warns of FMC static credential flaw exploited in zero-day attacks
→ No new info (linked only)
Tier C
VulDB60d ago
CVE-2026-20316 | Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure
→ No new info (linked only)
Tier A
Cisco Security60d ago
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-259
PublishedJul 29, 2026
Last enriched60d ago
Trending Score46
Source articles20
Independent12
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76460EXPKEV
Cisco Identity Services Engine Authentication Bypass Vulnerability
Trending: 104
CRITICALCVE-2026-76461EXPKEV
Cisco Secure Email Gateway SQL Injection Vulnerability
Trending: 60
CRITICALCVE-2026-76423
Cisco ISE API Authentication Bypass Vulnerability
Trending: 30
CRITICALCVE-2026-76440
Cisco Secure Email Gateway Security Hardening Release
Trending: 28
CRITICALCVE-2026-20353
Cisco Secure Email Gateway Security Hardening Release
Trending: 28

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 29, 2026
Discovered by ZDM
Jul 29, 2026