CVE-2026-20316 · High · CISA KEV
Cisco Secure Firewall Management Center Hard-Coded Password Vulnerability (KEV)
Threat Engine Auto-Feed · data current as of 2026-07-30
A hard-coded password vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to log in with low-privileged accounts. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. Attackers can access sensitive data within affected systems.
- CVSS:
- EPSS percentile: 0.52596
- Exploitation pressure: 57/100 (High)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 53th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves the use of a hard-coded password, meaning a password is permanently embedded within the software's code. This allows anyone who discovers the password to gain unauthorized access, bypassing standard authentication mechanisms.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using Cisco Secure Firewall Management Center (FMC)
- Financial services organizations (targeted by FIN7, LockBit affiliates, APT38)
- Technology sector organizations (targeted by APT29, Scattered Spider)
Misconfigurations that escalate it
- Lack of robust network segmentation that could limit access to FMC interfaces
- Insufficient monitoring for unauthorized access attempts to management interfaces
High-impact scenarios
- Unauthorized access to sensitive firewall configuration and operational data
- Potential for further network compromise through manipulation of firewall rules or settings
- Data exfiltration from the management system
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor logs for unusual login attempts or activity on Cisco Secure Firewall Management Center (FMC) devices, especially from unknown or unexpected sources.
- Regularly audit user accounts and permissions on FMC to identify any unauthorized or suspicious accounts.
Contain
- Isolate affected Cisco Secure Firewall Management Center (FMC) instances from the broader network if unauthorized access is detected, while maintaining essential management capabilities.
- Review and restrict network access to FMC management interfaces to only trusted administrative networks and hosts.
Patch
- Apply the latest security updates and patches from Cisco for Secure Firewall Management Center (FMC) as soon as they become available to address this hard-coded password vulnerability.
Frontier verdict — High
High priority due to active exploitation (CISA KEV) and potential for sensitive data access on critical network infrastructure.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.