
CISCO has warned of a flaw in its Firewall Management Center that lets attackers log in with hidden static credentials. Tracked as CVE-2026-20316 the issue is already being exploited and has been added to CISA’s Known Exploited Vulnerabilities catalogue.
The vulnerability resides in a hard‑coded account within the FMC web interface that can be used without authentication. It carries a CVSS v3.1 base score of 5.3 rated Medium. Affected releases include versions 7.0.0 7.0.1 7.0.2 and 7.2.0 among others. Successful login grants a low‑privileged shell from which an attacker can read or change firewall policies and logs.
Cisco’s advisory notes there are no workarounds and the only fix is to apply the hot‑fix released for each affected branch. The flaw is being actively exploited in the wild which prompted its addition to the KEV list. No specific threat actor has been publicly linked to the attacks so far.
The addition to the KEV catalogue means federal agencies must patch the issue within the timeframe set by CISA’s binding directive. While the CVSS score is moderate the ease of network‑only access makes it attractive for opportunistic intruders. The vulnerability highlights the risk of static credentials lingering in management platforms.
Administrators should verify which version of FMC is running and compare it to the list of affected releases in the Cisco advisory here. If a vulnerable release is identified they must download the appropriate hot‑fix from Cisco’s support site and apply it according to the upgrade instructions. After patching they should reset any passwords that may have been exposed and review logs for signs of unauthorized access.
Enforcing multi‑factor authentication for management interfaces where possible and restricting network access to the FMC web portal to trusted IP ranges reduces the chance of abuse. Regularly scanning for default or hard‑coded credentials in all devices should be part of a baseline hardening routine.