Cisco FMC static credentials exploited by attackers (CVE-2026-20316) – Help Net Security

Cisco FMC static credentials exploited by attackers (CVE-2026-20316) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-07-30 10:44:00

A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned.

Two FMC flaws, one indicator of compromise

CVE-2026-20316, reported by Jimi Sebree of Horizon3.ai, is found in the FMC software’s web interface. The static user credentials are for a low-privileged account, and they can be used by attackers to log in to an affected device and potentially access sensitive data.

Cisco noted that it could also be leveraged in conjunction with other vulnerabilities, potentially allowing attackers to gain elevated privileges and thus greater capacity for more in-depth compromise. (The company did not say such chaining was actually occurring.)

The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on Wednesday, ordering US civilian federal…