Use of Hard-coded Password in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20316

 

Use of Hard-coded Password in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-20316

Published: July 29, 2026 / Updated: July 29, 2026


Vulnerability identifier: #VU140037
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2026-20316
CWE-ID: CWE-259
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Affected software:
Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of static credentials in the web interface when handling login requests. A remote attacker can log in with a built-in low-privileged account to disclose sensitive information.

If the management interface does not have public internet access, the exposed attack surface is reduced.

Note, the vulnerability is being actively exploited in the wild.


How to mitigate CVE-2026-20316

Install security update from vendor's website.

Sources