What it is
CVE-2026-20316 is an unauthenticated vulnerability affecting Cisco Secure Firewall Management Center (FMC). A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an...
Vulnerability report
Cisco Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) · 7.0.0
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-20316 is an unauthenticated vulnerability affecting Cisco Secure Firewall Management Center (FMC). A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Cisco Secure Firewall Management Center (FMC) 7.0.0.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system.
A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2026-07-29 18:45 UTC |
| CVE | 2026-07-29 19:30 UTC |
| BleepingComputer | 2026-07-29 21:35 UTC |
| The Hacker News | 2026-07-30 05:08 UTC |
| Cisco PSIRT CSAF | 2026-08-11 19:01 UTC |
| Cisco Talos Blog | 2026-09-09 16:08 UTC |
| Cisco Security Advisory | 2026-09-16 18:17 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
35.1%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · The Hacker News
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse...
Read full advisoryRecent mention · The Hacker News
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesThe Hacker News · 17 Sep 2026
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just
Recent mention · NCSC Security Advisories
NCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management CenterNCSC Security Advisories · 11 Sep 2026
Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account. Hierdoor kunnen niet-geauthenticeerde externe aanvallers toegang verkrijgen zonder inloggegevens. Deze toegang kan leiden tot het blootstellen van gevoelige data die door het systeem wordt opgeslagen of beheerd. In combinatie met andere kwetsbaarheden kan deze toegang leiden tot privilege-escalatie. Het Amerikaanse CISA heeft de...
Recent mention · Cisco Talos Blog
We've got one word for it, and it's usually the wrong oneCisco Talos Blog · 10 Sep 2026
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
Recent mention · Cisco Talos Blog
Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiesCisco Talos Blog · 09 Sep 2026
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass VulnerabilityZero Day Initiative Published Advisories · 11 Aug 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-20316.
Recent mention · The Hacker News
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe Hacker News · 30 Jul 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
Recent mention · BleepingComputer
Cisco warns of FMC static credential flaw exploited in zero-day attacksBleepingComputer · 29 Jul 2026
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
Recent mention · Cisco Security Advisory
Cisco Secure Firewall Management Center Software Static Credential VulnerabilityCisco Security Advisory · 29 Jul 2026
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged...
Timeline
18:17 UTC
Exploitation attested by an external source
16:08 UTC
Exploitation attested by an external source
19:01 UTC
Exploitation attested by an external source
05:08 UTC
Exploitation attested by an external source
21:35 UTC
Exploitation attested by an external source
19:30 UTC
Exploitation attested by an external source
18:45 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
16:22 UTC
Vulnerability disclosed publicly
11:59 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-20316
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-20316",
"confidence": "Confirmed",
"cvss_score": 5.3,
"cvss_estimated": false,
"epss_score": 0.35096,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}