Use of Hard-coded Password in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20316
Published: July 29, 2026 / Updated: July 29, 2026
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of static credentials in the web interface when handling login requests. A remote attacker can log in with a built-in low-privileged account to disclose sensitive information.
If the management interface does not have public internet access, the exposed attack surface is reduced.
Note, the vulnerability is being actively exploited in the wild.