Start with Identity
← Blog
News

Cisco FMC shipped with hardcoded credentials, and attackers found them before the patch did

CVE-2026-20316 is a low-privileged account with credentials hardcoded into Cisco Secure Firewall Management Center, giving unauthenticated remote attackers access to sensitive system data. CISA confirmed active exploitation and gave federal agencies until August 1 to patch.

By SWI Community TeamJul 30, 2026Updated Aug 6, 2026

Cisco disclosed CVE-2026-20316 (CVSS 5.3) on July 30, 2026, a low-privileged account with credentials hardcoded directly into Cisco Secure Firewall Management Center software across versions 7.0 through 10.0. The static credentials let an unauthenticated remote attacker reach sensitive system data without ever needing to compromise a real account. CISA added the flaw to its Known Exploited Vulnerabilities catalog the day before disclosure, confirming active exploitation already underway by that point, and set an August 1 remediation deadline for federal civilian agencies, a two-day window. Cisco shipped hotfixes for every affected release and notes the attack surface shrinks considerably if the FMC management interface isn't reachable from the public internet. The bug can also chain with CVE-2026-20079 for privilege escalation to fuller access.

Why it matters

A hardcoded credential is a secret that was never supposed to be a secret in the first place, baked into the product rather than issued and rotatable, which is why the fix here is a software patch and not a password reset. Firewall management infrastructure is a particularly bad place for this class of bug: FMC is the control plane for the security devices protecting everything behind it.

Confirm your FMC deployment isn't reachable from the internet regardless of patch status, and treat this as a two-day-old actively exploited bug rather than a routine advisory given how tight the window was between KEV addition and the federal deadline.

Source: The Hacker News

Independent analysis. No vendor sponsorship.