Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-20316

Published 2026-07-29
Updated last month
Vendor/s
Cisco
Product/s
Secure Firewall Management Center (FMC)
Version/s
7.0.0 > 7.0.9
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
5.3
/ 10
Medium
Severity Details
Base score
5.3 Medium
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Description

CVE-2026-20316 is an actively exploited Cisco FMC vulnerability involving static credentials. Patch affected systems immediately to prevent unauthorized access.

CPE

Cisco logo
Cisco
Product Version Start Version End (excl.) Status
secure_firewall_management_center 7.0.0 7.0.9 vulnerable
secure_firewall_management_center 7.2.0 7.2.11 vulnerable
secure_firewall_management_center 7.3.0 7.3.1.2 vulnerable
secure_firewall_management_center 7.4.0 7.4.7 vulnerable
secure_firewall_management_center 7.6.0 7.6.5 vulnerable
secure_firewall_management_center 7.7.0 7.7.12 vulnerable
secure_firewall_management_center 10.0.0 10.0.1 vulnerable

Related weakness (CWE)

CWE-259

Remediation plan

1

Apply official patches

Cisco has released software updates to address this vulnerability by removing the static credentials. Consult the Cisco Security Advisory (cisco-sa-fmc-static-cred-BET3Cjh) for specific patch availability for your release train and apply them immediately.

2

Update affected systems

Immediately upgrade Cisco FMC software if running vulnerable versions including 7.0.x (up to 7.0.9), 7.2.x (up to 7.2.11), 7.3.x, 7.4.x, 7.6.x, 7.7.x, or 10.0.x. Ensure systems are moved to a fixed release version as specified in Cisco's technical documentation.

3

Restrict access

Limit access to the FMC management interface to trusted internal networks only. Use VPNs, access control lists (ACLs), or jump servers to ensure the web interface is not reachable from the public internet, which significantly reduces the attack surface.

4

Monitor for exploitation

Review web server logs and audit trails for successful logins from unexpected IP addresses using low-privileged accounts. Watch for subsequent suspicious activity that might indicate an attempt to elevate privileges or exfiltrate sensitive configuration data.

Detection Guidance

"Monitor Cisco FMC audit logs for successful logins to the web management interface from unexpected or external IP addresses, particularly those associated with low-privileged accounts. Use network security monitoring to identify unauthorized HTTPS traffic to the FMC. Since this vulnerability is often chained, look for subsequent indicators of privilege escalation or unusual configuration changes. Review CISA’s 'Forensics Triage Requirements' for specific guidance on identifying compromise in Cisco environments."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management