Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

cve CVE-2026-20316 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Re… the claim

What it is to other things

affectscisco/secure_firewall_management_center
NVD
made_bycisco
NVD

In words only, so not counted until a person confirms one:

affectscisco/cisco_secure_firewall_management_center_fmc
NVD says “Cisco · Cisco Secure Firewall Management Center (FMC)”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Secure Firewall Management Center (FMC)",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "7.0.0"
              },
              {
                "status": "affected",
                "version": "7.0.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.2"
              },
              {
                "status": "affected",
                "version": "7.2.0"
              },
              {
                "status": "affected",
                "version": "7.0.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.3"
              },
              {
                "status": "affected",
                "version": "7.2.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.4"
              },
              {
                "status": "affected",
                "version": "7.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.5"
              },
              {
                "status": "affected",
                "version": "7.3.0"
              },
              {
                "status": "affected",
                "version": "7.2.2"
              },
              {
                "status": "affected",
                "version": "7.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.3"
              },
              {
                "status": "affected",
                "version": "7.2.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.4"
              },
              {
                "status": "affected",
                "version": "7.0.6"
              },
              {
                "status": "affected",
                "version": "7.2.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.5"
              },
              {
                "status": "affected",
                "version": "7.3.1.1"
              },
              {
                "status": "affected",
                "version": "7.4.0"
              },
              {
                "status": "affected",
                "version": "7.0.6.1"
              },
              {
                "status": "affected",
                "version": "7.2.5.1"
              },
              {
                "status": "affected",
                "version": "7.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.6"
              },
              {
                "status": "affected",
                "version": "7.4.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.2"
              },
              {
                "status": "affected",
                "version": "7.2.7"
              },
              {
                "status": "affected",
                "version": "7.2.5.2"
              },
              {
                "status": "affected",
                "version": "7.3.1.2"
              },
              {
                "status": "affected",
                "version": "7.2.8"
              },
              {
                "status": "affected",
                "version": "7.6.0"
              },
              {
                "status": "affected",
                "version": "7.4.2"
              },
              {
                "status": "affected",
                "version": "7.2.8.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.3"
              },
              {
                "status": "affected",
                "version": "7.4.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.9"
              },
              {
                "status": "affected",
                "version": "7.0.7"
              },
              {
                "status": "affected",
                "version": "7.7.0"
              },
              {
                "status": "affected",
                "version": "7.4.2.2"
              },
              {
                "status": "affected",
                "version": "7.2.10"
              },
              {
                "status": "affected",
                "version": "7.6.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.3"
              },
              {
                "status": "affected",
                "version": "7.0.8"
              },
              {
                "status": "affected",
                "version": "7.6.2"
              },
              {
                "status": "affected",
                "version": "7.7.10"
              },
              {
                "status": "affected",
                "version": "7.2.10.1"
              },
              {
                "status": "affected",
                "version": "7.0.8.1"
              },
              {
                "status": "affected",
                "version": "7.6.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.10.2"
              },
              {
                "status": "affected",
                "version": "7.7.10.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.4"
              },
              {
                "status": "affected",
                "version": "7.4.3"
              },
              {
                "status": "affected",
                "version": "7.6.3"
              },
              {
                "status": "affected",
                "version": "7.7.11"
              },
              {
                "status": "affected",
                "version": "7.6.4"
              },
              {
                "status": "affected",
                "version": "10.0.0"
              },
              {
                "status": "affected",
                "version": "7.4.4"
              },
              {
                "status": "affected",
                "version": "7.4.5"
              },
              {
                "status": "affected",
                "version": "7.0.9"
              },
              {
                "status": "affected",
                "version": "7.2.11"
              },
              {
                "status": "affected",
                "version": "7.7.12"
              },
              {
                "status": "affected",
                "version": "7.6.5"
              },
              {
                "status": "affected",
                "version": "7.4.6"
              },
              {
                "status": "affected",
                "version": "10.0.1"
              },
              {
                "status": "affected",
                "version": "7.4.7"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "cisaActionDue": "2026-08-01",
    "cisaExploitAdd": "2026-07-29",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD0173-E045-4EF0-BC97-45BBFCFA1502",
                "versionEndIncluding": "7.0.9",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9DBBB745-D7D2-4E11-ACC7-CE880B066D1E",
                "versionEndIncluding": "7.2.11",
                "versionStartIncluding": "7.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5CA67B3C-60F2-4373-81B6-FCA063518CB1",
                "versionEndIncluding": "7.3.1.2",
                "versionStartIncluding": "7.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CD49AB20-6E0A-4C1A-A775-D2EEA55D45D8",
                "versionEndIncluding": "7.4.7",
                "versionStartIncluding": "7.4.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9340872F-6A25-467A-BC63-957E1B7E817D",
                "versionEndIncluding": "7.6.5",
                "versionStartIncluding": "7.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF37EF84-93E8-4D2F-BFEF-7754B74D1E3F",
                "versionEndIncluding": "7.7.12",
                "versionStartIncluding": "7.7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7A5384FA-2700-4284-8AAD-27B8923732F3",
                "versionEndIncluding": "10.0.1",
                "versionStartIncluding": "10.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. \r\nNote: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  \r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges."
      }
    ],
    "id": "CVE-2026-20316",
    "lastModified": "2026-09-16T21:17:10.150",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20316",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-29T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-29T17:16:51.840",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-259"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-259
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-259
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2026-08-01
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2026-08-01
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesKnown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Known
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—
Product
product
not compared
CISA Known Exploited VulnerabilitiesSecure Firewall Management Center (FMC)
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Secure Firewall Management Center (FMC)
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—
Product
product
not compared
NVDCisco Secure Firewall Management Center (FMC)
receipt
Source
NVD
Its words
Cisco Secure Firewall Management Center (FMC)
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco Secure Firewall Management Center (FMC)
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Secure Firewall Management Center (FMC)",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "7.0.0"
              },
              {
                "status": "affected",
                "version": "7.0.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.2"
              },
              {
                "status": "affected",
                "version": "7.2.0"
              },
              {
                "status": "affected",
                "version": "7.0.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.3"
              },
              {
                "status": "affected",
                "version": "7.2.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.4"
              },
              {
                "status": "affected",
                "version": "7.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.5"
              },
              {
                "status": "affected",
                "version": "7.3.0"
              },
              {
                "status": "affected",
                "version": "7.2.2"
              },
              {
                "status": "affected",
                "version": "7.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.3"
              },
              {
                "status": "affected",
                "version": "7.2.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.4"
              },
              {
                "status": "affected",
                "version": "7.0.6"
              },
              {
                "status": "affected",
                "version": "7.2.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.5"
              },
              {
                "status": "affected",
                "version": "7.3.1.1"
              },
              {
                "status": "affected",
                "version": "7.4.0"
              },
              {
                "status": "affected",
                "version": "7.0.6.1"
              },
              {
                "status": "affected",
                "version": "7.2.5.1"
              },
              {
                "status": "affected",
                "version": "7.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.6"
              },
              {
                "status": "affected",
                "version": "7.4.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.2"
              },
              {
                "status": "affected",
                "version": "7.2.7"
              },
              {
                "status": "affected",
                "version": "7.2.5.2"
              },
              {
                "status": "affected",
                "version": "7.3.1.2"
              },
              {
                "status": "affected",
                "version": "7.2.8"
              },
              {
                "status": "affected",
                "version": "7.6.0"
              },
              {
                "status": "affected",
                "version": "7.4.2"
              },
              {
                "status": "affected",
                "version": "7.2.8.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.3"
              },
              {
                "status": "affected",
                "version": "7.4.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.9"
              },
              {
                "status": "affected",
                "version": "7.0.7"
              },
              {
                "status": "affected",
                "version": "7.7.0"
              },
              {
                "status": "affected",
                "version": "7.4.2.2"
              },
              {
                "status": "affected",
                "version": "7.2.10"
              },
              {
                "status": "affected",
                "version": "7.6.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.3"
              },
              {
                "status": "affected",
                "version": "7.0.8"
              },
              {
                "status": "affected",
                "version": "7.6.2"
              },
              {
                "status": "affected",
                "version": "7.7.10"
              },
              {
                "status": "affected",
                "version": "7.2.10.1"
              },
              {
                "status": "affected",
                "version": "7.0.8.1"
              },
              {
                "status": "affected",
                "version": "7.6.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.10.2"
              },
              {
                "status": "affected",
                "version": "7.7.10.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.4"
              },
              {
                "status": "affected",
                "version": "7.4.3"
              },
              {
                "status": "affected",
                "version": "7.6.3"
              },
              {
                "status": "affected",
                "version": "7.7.11"
              },
              {
                "status": "affected",
                "version": "7.6.4"
              },
              {
                "status": "affected",
                "version": "10.0.0"
              },
              {
                "status": "affected",
                "version": "7.4.4"
              },
              {
                "status": "affected",
                "version": "7.4.5"
              },
              {
                "status": "affected",
                "version": "7.0.9"
              },
              {
                "status": "affected",
                "version": "7.2.11"
              },
              {
                "status": "affected",
                "version": "7.7.12"
              },
              {
                "status": "affected",
                "version": "7.6.5"
              },
              {
                "status": "affected",
                "version": "7.4.6"
              },
              {
                "status": "affected",
                "version": "10.0.1"
              },
              {
                "status": "affected",
                "version": "7.4.7"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "cisaActionDue": "2026-08-01",
    "cisaExploitAdd": "2026-07-29",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD0173-E045-4EF0-BC97-45BBFCFA1502",
                "versionEndIncluding": "7.0.9",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9DBBB745-D7D2-4E11-ACC7-CE880B066D1E",
                "versionEndIncluding": "7.2.11",
                "versionStartIncluding": "7.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5CA67B3C-60F2-4373-81B6-FCA063518CB1",
                "versionEndIncluding": "7.3.1.2",
                "versionStartIncluding": "7.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CD49AB20-6E0A-4C1A-A775-D2EEA55D45D8",
                "versionEndIncluding": "7.4.7",
                "versionStartIncluding": "7.4.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9340872F-6A25-467A-BC63-957E1B7E817D",
                "versionEndIncluding": "7.6.5",
                "versionStartIncluding": "7.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF37EF84-93E8-4D2F-BFEF-7754B74D1E3F",
                "versionEndIncluding": "7.7.12",
                "versionStartIncluding": "7.7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7A5384FA-2700-4284-8AAD-27B8923732F3",
                "versionEndIncluding": "10.0.1",
                "versionStartIncluding": "10.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. \r\nNote: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  \r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges."
      }
    ],
    "id": "CVE-2026-20316",
    "lastModified": "2026-09-16T21:17:10.150",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20316",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-29T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-29T17:16:51.840",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-259"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Secure Firewall Management Center (FMC)",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "7.0.0"
              },
              {
                "status": "affected",
                "version": "7.0.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.2"
              },
              {
                "status": "affected",
                "version": "7.2.0"
              },
              {
                "status": "affected",
                "version": "7.0.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.3"
              },
              {
                "status": "affected",
                "version": "7.2.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.4"
              },
              {
                "status": "affected",
                "version": "7.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.5"
              },
              {
                "status": "affected",
                "version": "7.3.0"
              },
              {
                "status": "affected",
                "version": "7.2.2"
              },
              {
                "status": "affected",
                "version": "7.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.3"
              },
              {
                "status": "affected",
                "version": "7.2.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.4"
              },
              {
                "status": "affected",
                "version": "7.0.6"
              },
              {
                "status": "affected",
                "version": "7.2.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.5"
              },
              {
                "status": "affected",
                "version": "7.3.1.1"
              },
              {
                "status": "affected",
                "version": "7.4.0"
              },
              {
                "status": "affected",
                "version": "7.0.6.1"
              },
              {
                "status": "affected",
                "version": "7.2.5.1"
              },
              {
                "status": "affected",
                "version": "7.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.6"
              },
              {
                "status": "affected",
                "version": "7.4.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.2"
              },
              {
                "status": "affected",
                "version": "7.2.7"
              },
              {
                "status": "affected",
                "version": "7.2.5.2"
              },
              {
                "status": "affected",
                "version": "7.3.1.2"
              },
              {
                "status": "affected",
                "version": "7.2.8"
              },
              {
                "status": "affected",
                "version": "7.6.0"
              },
              {
                "status": "affected",
                "version": "7.4.2"
              },
              {
                "status": "affected",
                "version": "7.2.8.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.3"
              },
              {
                "status": "affected",
                "version": "7.4.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.9"
              },
              {
                "status": "affected",
                "version": "7.0.7"
              },
              {
                "status": "affected",
                "version": "7.7.0"
              },
              {
                "status": "affected",
                "version": "7.4.2.2"
              },
              {
                "status": "affected",
                "version": "7.2.10"
              },
              {
                "status": "affected",
                "version": "7.6.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.3"
              },
              {
                "status": "affected",
                "version": "7.0.8"
              },
              {
                "status": "affected",
                "version": "7.6.2"
              },
              {
                "status": "affected",
                "version": "7.7.10"
              },
              {
                "status": "affected",
                "version": "7.2.10.1"
              },
              {
                "status": "affected",
                "version": "7.0.8.1"
              },
              {
                "status": "affected",
                "version": "7.6.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.10.2"
              },
              {
                "status": "affected",
                "version": "7.7.10.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.4"
              },
              {
                "status": "affected",
                "version": "7.4.3"
              },
              {
                "status": "affected",
                "version": "7.6.3"
              },
              {
                "status": "affected",
                "version": "7.7.11"
              },
              {
                "status": "affected",
                "version": "7.6.4"
              },
              {
                "status": "affected",
                "version": "10.0.0"
              },
              {
                "status": "affected",
                "version": "7.4.4"
              },
              {
                "status": "affected",
                "version": "7.4.5"
              },
              {
                "status": "affected",
                "version": "7.0.9"
              },
              {
                "status": "affected",
                "version": "7.2.11"
              },
              {
                "status": "affected",
                "version": "7.7.12"
              },
              {
                "status": "affected",
                "version": "7.6.5"
              },
              {
                "status": "affected",
                "version": "7.4.6"
              },
              {
                "status": "affected",
                "version": "10.0.1"
              },
              {
                "status": "affected",
                "version": "7.4.7"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "cisaActionDue": "2026-08-01",
    "cisaExploitAdd": "2026-07-29",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD0173-E045-4EF0-BC97-45BBFCFA1502",
                "versionEndIncluding": "7.0.9",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9DBBB745-D7D2-4E11-ACC7-CE880B066D1E",
                "versionEndIncluding": "7.2.11",
                "versionStartIncluding": "7.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5CA67B3C-60F2-4373-81B6-FCA063518CB1",
                "versionEndIncluding": "7.3.1.2",
                "versionStartIncluding": "7.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CD49AB20-6E0A-4C1A-A775-D2EEA55D45D8",
                "versionEndIncluding": "7.4.7",
                "versionStartIncluding": "7.4.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9340872F-6A25-467A-BC63-957E1B7E817D",
                "versionEndIncluding": "7.6.5",
                "versionStartIncluding": "7.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF37EF84-93E8-4D2F-BFEF-7754B74D1E3F",
                "versionEndIncluding": "7.7.12",
                "versionStartIncluding": "7.7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7A5384FA-2700-4284-8AAD-27B8923732F3",
                "versionEndIncluding": "10.0.1",
                "versionStartIncluding": "10.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. \r\nNote: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  \r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges."
      }
    ],
    "id": "CVE-2026-20316",
    "lastModified": "2026-09-16T21:17:10.150",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20316",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-29T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-29T17:16:51.840",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-259"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDCisco
receipt
Source
NVD
Its words
Cisco
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "Cisco Secure Firewall Management Center (FMC)",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "7.0.0"
              },
              {
                "status": "affected",
                "version": "7.0.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.2"
              },
              {
                "status": "affected",
                "version": "7.2.0"
              },
              {
                "status": "affected",
                "version": "7.0.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.3"
              },
              {
                "status": "affected",
                "version": "7.2.0.1"
              },
              {
                "status": "affected",
                "version": "7.0.4"
              },
              {
                "status": "affected",
                "version": "7.2.1"
              },
              {
                "status": "affected",
                "version": "7.0.5"
              },
              {
                "status": "affected",
                "version": "7.3.0"
              },
              {
                "status": "affected",
                "version": "7.2.2"
              },
              {
                "status": "affected",
                "version": "7.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.3"
              },
              {
                "status": "affected",
                "version": "7.2.3.1"
              },
              {
                "status": "affected",
                "version": "7.2.4"
              },
              {
                "status": "affected",
                "version": "7.0.6"
              },
              {
                "status": "affected",
                "version": "7.2.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.5"
              },
              {
                "status": "affected",
                "version": "7.3.1.1"
              },
              {
                "status": "affected",
                "version": "7.4.0"
              },
              {
                "status": "affected",
                "version": "7.0.6.1"
              },
              {
                "status": "affected",
                "version": "7.2.5.1"
              },
              {
                "status": "affected",
                "version": "7.4.1"
              },
              {
                "status": "affected",
                "version": "7.2.6"
              },
              {
                "status": "affected",
                "version": "7.4.1.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.2"
              },
              {
                "status": "affected",
                "version": "7.2.7"
              },
              {
                "status": "affected",
                "version": "7.2.5.2"
              },
              {
                "status": "affected",
                "version": "7.3.1.2"
              },
              {
                "status": "affected",
                "version": "7.2.8"
              },
              {
                "status": "affected",
                "version": "7.6.0"
              },
              {
                "status": "affected",
                "version": "7.4.2"
              },
              {
                "status": "affected",
                "version": "7.2.8.1"
              },
              {
                "status": "affected",
                "version": "7.0.6.3"
              },
              {
                "status": "affected",
                "version": "7.4.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.9"
              },
              {
                "status": "affected",
                "version": "7.0.7"
              },
              {
                "status": "affected",
                "version": "7.7.0"
              },
              {
                "status": "affected",
                "version": "7.4.2.2"
              },
              {
                "status": "affected",
                "version": "7.2.10"
              },
              {
                "status": "affected",
                "version": "7.6.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.3"
              },
              {
                "status": "affected",
                "version": "7.0.8"
              },
              {
                "status": "affected",
                "version": "7.6.2"
              },
              {
                "status": "affected",
                "version": "7.7.10"
              },
              {
                "status": "affected",
                "version": "7.2.10.1"
              },
              {
                "status": "affected",
                "version": "7.0.8.1"
              },
              {
                "status": "affected",
                "version": "7.6.2.1"
              },
              {
                "status": "affected",
                "version": "7.2.10.2"
              },
              {
                "status": "affected",
                "version": "7.7.10.1"
              },
              {
                "status": "affected",
                "version": "7.4.2.4"
              },
              {
                "status": "affected",
                "version": "7.4.3"
              },
              {
                "status": "affected",
                "version": "7.6.3"
              },
              {
                "status": "affected",
                "version": "7.7.11"
              },
              {
                "status": "affected",
                "version": "7.6.4"
              },
              {
                "status": "affected",
                "version": "10.0.0"
              },
              {
                "status": "affected",
                "version": "7.4.4"
              },
              {
                "status": "affected",
                "version": "7.4.5"
              },
              {
                "status": "affected",
                "version": "7.0.9"
              },
              {
                "status": "affected",
                "version": "7.2.11"
              },
              {
                "status": "affected",
                "version": "7.7.12"
              },
              {
                "status": "affected",
                "version": "7.6.5"
              },
              {
                "status": "affected",
                "version": "7.4.6"
              },
              {
                "status": "affected",
                "version": "10.0.1"
              },
              {
                "status": "affected",
                "version": "7.4.7"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "cisaActionDue": "2026-08-01",
    "cisaExploitAdd": "2026-07-29",
    "cisaRequiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
    "cisaVulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD0173-E045-4EF0-BC97-45BBFCFA1502",
                "versionEndIncluding": "7.0.9",
                "versionStartIncluding": "7.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9DBBB745-D7D2-4E11-ACC7-CE880B066D1E",
                "versionEndIncluding": "7.2.11",
                "versionStartIncluding": "7.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "5CA67B3C-60F2-4373-81B6-FCA063518CB1",
                "versionEndIncluding": "7.3.1.2",
                "versionStartIncluding": "7.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "CD49AB20-6E0A-4C1A-A775-D2EEA55D45D8",
                "versionEndIncluding": "7.4.7",
                "versionStartIncluding": "7.4.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9340872F-6A25-467A-BC63-957E1B7E817D",
                "versionEndIncluding": "7.6.5",
                "versionStartIncluding": "7.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF37EF84-93E8-4D2F-BFEF-7754B74D1E3F",
                "versionEndIncluding": "7.7.12",
                "versionStartIncluding": "7.7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7A5384FA-2700-4284-8AAD-27B8923732F3",
                "versionEndIncluding": "10.0.1",
                "versionStartIncluding": "10.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. \r\nNote: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  \r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges."
      }
    ],
    "id": "CVE-2026-20316",
    "lastModified": "2026-09-16T21:17:10.150",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-20316",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-07-29T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-07-29T17:16:51.840",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-259"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesCisco
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Cisco
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:00 UTC
What the source handed over
{
  "cveID": "CVE-2026-20316",
  "cwes": "CWE-259",
  "dateAdded": "2026-07-29",
  "dueDate": "2026-08-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316",
  "product": "Secure Firewall Management Center (FMC)",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.",
  "vendorProject": "Cisco",
  "vulnerabilityName": "Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
}
—

vulnerability

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
zetlyn/cve-kev · 2026-07-29
cwes CWE-259 due_date 2026-08-01 exploited yes forensic_triage false known_ransomware_campaign_use Known product Secure Firewall Management Center (FMC) vendor_project Cisco
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
zetlyn/cve-nvd · 2026-07-29
cvss 5.3 product Cisco Secure Firewall Management Center (FMC) status Analyzed vendor Cisco source