What it is
CVE-2026-20316 is an unauthenticated vulnerability affecting Cisco Cisco Secure Firewall Management Center (FMC). A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could...
Vulnerability report
Cisco Secure Firewall Management Center (FMC)
Cisco / Cisco Secure Firewall Management Center (FMC) · 7.0.0
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-20316 is an unauthenticated vulnerability affecting Cisco Cisco Secure Firewall Management Center (FMC). A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
Cisco / Cisco Secure Firewall Management Center (FMC) 7.0.0.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system.
A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
Independent exploitation attestation added to the KEV Intelligence record.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2026-07-29 18:45 UTC |
| CVE | 2026-07-29 19:30 UTC |
| BleepingComputer | 2026-07-29 21:35 UTC |
| TheHackerNews | 2026-07-30 05:08 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
No scanner integrations recorded yet.
No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.8%
Recent mention · Zero Day Initiative Published Advisories
This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned:...
Read full advisoryRecent mention · Zero Day Initiative Published Advisories
ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass VulnerabilityZero Day Initiative Published Advisories · 11 Aug 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-20316.
Recent mention · TheHackerNews
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataTheHackerNews · 30 Jul 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
Recent mention · BleepingComputer
Cisco warns of FMC static credential flaw exploited in zero-day attacksBleepingComputer · 29 Jul 2026
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
Recent mention · Cisco Security Advisory
Cisco Secure Firewall Management Center Software Static Credential VulnerabilityCisco Security Advisory · 29 Jul 2026
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged...
Timeline
Exploitation attested by an external source
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-20316
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-20316",
"confidence": "Confirmed",
"cvss_score": 5.3,
"cvss_estimated": false,
"epss_score": 0.00788,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.