SB2026072974 - Use of hard-coded credentials in KnowledgeDeliver Cisco Secure Firewall Management Center
Published: July 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Hard-coded Password (CVE-ID: CVE-2026-20316)
CWE-ID: CWE-259 - Use of Hard-coded Password
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of static credentials in the web interface when handling login requests. A remote attacker can log in with a built-in low-privileged account to disclose sensitive information.
If the management interface does not have public internet access, the exposed attack surface is reduced.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.