Skip to main content

Cisco Releases Security Advisory for Vulnerability in Secure Firewall Management Center

Successful exploitation of CVE-2026-20316 could allow an unauthenticated remote attacker to log into an affected device using a low-privileged account and access sensitive information

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-20316 could allow an unauthenticated remote attacker to log into an affected device using a low-privileged account and access sensitive information


Threat details

Exploitation of CVE-2026-20316

Cisco has confirmed that CVE-2026-20316 has been actively exploited in the wild and the vulnerability has been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog. 

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Cisco has released a security advisory to address a high severity vulnerability in Cisco Secure Firewall Management Center (FMC) Software. Successful exploitation could allow an unauthenticated remote attacker to log into an affected device using a low-privileged account and access sensitive information.

  • CVE-2026-20316 - A use of hard-coded credentials vulnerability - CVSS v3.1 Base Score: 5.3

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

This vulnerability may be chained with other Cisco Secure FMC Software vulnerabilities to achieve privilege escalation; however, Cisco has not disclosed which specific vulnerabilities can be chained with CVE-2026-20316.


Remediation advice

Affected organisations are encouraged to review Cisco advisory cisco-sa-fmc-static-cred-BET3Cjh and apply the relevant update as soon as possible.



Last edited: 30 July 2026 1:53 pm