FMC static credentials leak sensitive data (CVE-2026-20316)
CVE-2026-20316
CVE-2026-20316: Cisco Secure FMC static credentials allow unauthenticated low-privileged login, leaking sensitive data. Exploited in the wild. Update to patched version.
Actively exploited in the wild - CVE-2026-20316 is a medium severity vulnerability in Cisco Secure Firewall Management Center (FMC) Software that uses static credentials, letting an unauthenticated attacker log in as a low-privileged user and access sensitive data. Patch immediately - active exploitation confirmed by CISA.
Overview
CVE-2026-20316 affects Cisco Secure Firewall Management Center (FMC) Software. The vulnerability stems from hardcoded, static user credentials for a low-privileged account within the web interface. An unauthenticated, remote attacker can use these credentials to log into the FMC management interface without any prior knowledge or authentication.
A successful exploitation allows the attacker to access sensitive data within the affected system at the low-privileged user level. While this account does not grant full administrative control, Cisco notes that it can be combined with other FMC vulnerabilities to achieve privilege escalation, raising the overall risk. The attack surface is reduced if the FMC management interface is not exposed to the public internet.
Impact
An attacker exploiting this flaw gains a foothold into the FMC environment. They can read sensitive configuration data, network topology information, and other internal details that could aid in further attacks. The CVSS score of 5.3 (Medium) reflects the low-privilege access, but the confirmed active exploitation and potential for privilege elevation make this a critical priority for defenders. Any FMC with a publicly accessible management interface is at immediate risk.
Remediation
Cisco has released software updates to address CVE-2026-20316. Affected organizations should:
- Update Cisco Secure FMC to the patched version specified in the Cisco Security Advisory. Apply the update to all FMC instances, especially those exposed to the internet.
- Review Access Logs for unauthorized low-privileged logins from unknown IP addresses.
- Restrict Management Access as a mitigation: if the FMC management interface does not require public internet access, block it at the firewall or boundary router to reduce the attack surface.
- Monitor for Lateral Movement since this initial foothold could be used with other vulnerabilities.
References
For background on recent active exploitation and related threats, see:
- Weekly Threat Roundup: 56M Credentials Leaked (June 15-21)
- Cisco Releases Security Updates for Actively Exploited
- Weekly Threat Roundup: Ivanti & Chrome Zero-Days (June 8-14)
Security Insight
The active exploitation of a static-credential issue in a major security appliance underscores a recurring theme: even vendors in the security space ship hardcoded secrets that bypass their own authentication controls. This mirrors past incidents in Cisco’s SD-WAN Manager and other enterprise appliances. The fact that a low-privilege account is sufficient to access sensitive data, combined with the potential for lateral privilege escalation, suggests that network segmentation and the principle of least privilege remain essential even for well-known vendors.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials....
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an af...
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is p...
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents ...