CVE-2026-20316 - Cisco Secure Firewall Management Center Static Credentials
Severity: MEDIUM (CVSS 5.3) | KEV Status: Actively Exploited
Affected Product:
- Cisco Secure Firewall Management Center (FMC) Software
Vulnerability Details: Static user credentials exist for a low-privileged account in the FMC web interface, allowing unauthenticated remote attackers to log in and access sensitive data. Cisco has assigned a High Security Impact Rating due to potential for privilege escalation when chained with other FMC vulnerabilities.
Attack Prerequisites:
- Management interface must be internet-accessible (risk reduced if not publicly exposed)
- No authentication required for initial access
Remediation:
- Apply vendor patches from Cisco Security Advisory cisco-sa-fmc-static-cred-BET3Cjh
- If not already deployed, restrict FMC management interface access to trusted networks only
- Prioritize remediation given active exploitation
References: