Cisco's firewall management tool shipped with a hidden login — and attackers found it first

CVE-2026-20316 is a static-credential bug in Secure FMC that's already on CISA's Known Exploited Vulnerabilities list, with a federal patch deadline…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-20316 is a hardcoded credential for a low-privilege account built into Cisco Secure FMC Software.

The short version

CVSS is only 5.3, but Cisco rated it High severity because the account's access can be chained with other FMC bugs to escalate privileges.

The short version

Affects FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco has hotfixes for all of them — there is no workaround.

The short version

CISA added it to the Known Exploited Vulnerabilities catalog on July 29, 2026, giving federal agencies until August 1, 2026 to patch.

The short version

Reported by Jimi Sebree of Horizon3.ai. Cisco has published indicators of compromise to help defenders check whether they've already been hit.

My honest read

A hardcoded credential in a firewall management console is about as bad as this category of bug gets, regardless of what the CVSS math says — this is the tool that controls your actual perimeter…

Aliteq

Read the full story

Cisco's firewall management tool shipped with a hidden login — and attackers found it first

Read the full story on Aliteq