CVE-2026-20316 · High · CISA KEV

Cisco Secure Firewall Management Center Hard-Coded Password Vulnerability (KEV)

Threat Engine Auto-Feed · data current as of 2026-07-30

A hard-coded password vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to log in with low-privileged accounts. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. Attackers can access sensitive data within affected systems.

  • CVSS:
  • EPSS percentile: 0.52596
  • Exploitation pressure: 57/100 (High)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 53th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves the use of a hard-coded password, meaning a password is permanently embedded within the software's code. This allows anyone who discovers the password to gain unauthorized access, bypassing standard authentication mechanisms.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using Cisco Secure Firewall Management Center (FMC)
  • Financial services organizations (targeted by FIN7, LockBit affiliates, APT38)
  • Technology sector organizations (targeted by APT29, Scattered Spider)

Misconfigurations that escalate it

  • Lack of robust network segmentation that could limit access to FMC interfaces
  • Insufficient monitoring for unauthorized access attempts to management interfaces

High-impact scenarios

  • Unauthorized access to sensitive firewall configuration and operational data
  • Potential for further network compromise through manipulation of firewall rules or settings
  • Data exfiltration from the management system

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor logs for unusual login attempts or activity on Cisco Secure Firewall Management Center (FMC) devices, especially from unknown or unexpected sources.
  • Regularly audit user accounts and permissions on FMC to identify any unauthorized or suspicious accounts.

Contain

  • Isolate affected Cisco Secure Firewall Management Center (FMC) instances from the broader network if unauthorized access is detected, while maintaining essential management capabilities.
  • Review and restrict network access to FMC management interfaces to only trusted administrative networks and hosts.

Patch

  • Apply the latest security updates and patches from Cisco for Secure Firewall Management Center (FMC) as soon as they become available to address this hard-coded password vulnerability.

Frontier verdict — High

High priority due to active exploitation (CISA KEV) and potential for sensitive data access on critical network infrastructure.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.