SB2026072974 - Use of hard-coded credentials in KnowledgeDeliver Cisco Secure Firewall Management Center



SB2026072974 - Use of hard-coded credentials in KnowledgeDeliver Cisco Secure Firewall Management Center

Published: July 29, 2026

Security Bulletin ID SB2026072974
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use of Hard-coded Password (CVE-ID: CVE-2026-20316)

CWE-ID: CWE-259 - Use of Hard-coded Password

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of static credentials in the web interface when handling login requests. A remote attacker can log in with a built-in low-privileged account to disclose sensitive information.

If the management interface does not have public internet access, the exposed attack surface is reduced.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.