Cisco's firewall management tool had a hardcoded password. attackers found it before Cisco did

CVE-2026-20316 gives anyone the login to a low-privilege account baked into Cisco Secure FMC — and Cisco's own team says it was already being used…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-20316 is a static, hardcoded credential for a low-privileged account built into Cisco Secure Firewall Management Center (FMC).

The short version

It carries a CVSS score of only 5.3 — but Cisco rates it High severity because it can be chained with other FMC bugs to escalate privileges.

The short version

Cisco's PSIRT confirmed active exploitation in the wild in July 2026, before a patch existed — a genuine zero-day.

The short version

CISA added it to the Known Exploited Vulnerabilities catalog on July 29, 2026, with a federal patch deadline of August 1.

The short version

Hotfixes exist for FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. Cisco is also telling everyone to rotate all credentials, keys and certificates, not just apply the patch.

My take

The part I keep coming back to is that this was a genuine zero-day — Cisco's own PSIRT says exploitation started before a fix existed, not after. A vendor building static credentials into a…

Aliteq

Read the full story

Cisco's firewall management tool had a hardcoded password. attackers found it before Cisco did

Read the full story on Aliteq