Cisco Firewall Management Center Zero-Day (CVE-2026-20316) Exploited in the Wild — CISA Sets August 1 Deadline
A hardcoded low-privilege credential in Cisco Secure Firewall Management Center is being actively exploited. CISA added it to its Known Exploited Vulnerabilities catalog with a patch deadline for federal agencies.
Cisco published an advisory on July 29 for CVE-2026-20316, a static-credential vulnerability in Secure Firewall Management Center (FMC) that CISA confirmed is already being exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog the same day it was disclosed and gave covered federal agencies until August 1 to patch — a two-day window that signals how seriously the agency is treating active exploitation, not just theoretical risk.
The flaw itself carries a CVSS base score of only 5.3, which undersells the danger. Cisco hardcoded credentials for a low-privileged user account into FMC’s web interface. A remote, unauthenticated attacker with network access to the management interface can authenticate with that static account and pull sensitive data out of the system — no password guessing, no phishing, just a credential that shipped baked into the product. Cisco assigned it a high Security Impact Rating specifically because it can be chained with other FMC vulnerabilities to escalate from that low-privileged foothold to full control.
Affected products are Cisco Secure Firewall Management Center Software running the on-premises deployment. Cisco explicitly excluded Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control — so this is squarely an on-prem management-plane issue, not a Cisco-wide firewall problem.
What to do now: Patch to the fixed FMC release Cisco lists in its advisory (cisco-sa-fmc-static-cred-BET3Cjh) immediately — this isn’t a “schedule it for next maintenance window” bug given confirmed active exploitation. If you can’t patch immediately, restrict management-interface access to a trusted management network or VPN only; the vulnerability requires network reachability to the web interface, so cutting that exposure is an effective stopgap. After patching, audit FMC access logs for authentication using the low-privileged account name Cisco’s advisory identifies, since exploitation may have already occurred before the patch was available.
This follows a pattern that’s become routine in 2026: management-plane software — the tools admins use to control security infrastructure — is now a bigger target than the infrastructure itself. A hardcoded credential in a firewall manager is a worse outcome than the same flaw in a random SaaS app, because compromising FMC gives an attacker visibility and potential control over every firewall it manages. If you run Secure Firewall Management Center on-prem, treat this as a today problem, not a this-week problem.
Sources
Related reading
- Cybersecurity CISA Adds 8 Actively Exploited Flaws to KEV, Including Three Cisco SD-WAN Zero-Days
- Cybersecurity Federal Agencies Have Until Tomorrow to Patch an Actively Exploited AD FS Zero-Day
- Cybersecurity Cisco's 7th SD-WAN Zero-Day of 2026: CVE-2026-20245 Enables Root Execution — No Patch Available