CVE-2026-20316

MEDIUM CVSS 3.1: 5.3 EPSS 0.79% ACTIVE EXPLOIT
Updated Aug 01, 2026
Cisco

CISA Known Exploited Vulnerability (KEV)

This vulnerability is actively exploited in the wild. Immediate patching is strongly recommended.

Due Date: Aug 01, 2026

Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions 10.0.0 — 7.7.12
Type CWE-259
Vendor Cisco
Public PoC Yes

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system.

A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 7

Configuration From (including) Up to (excluding)
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
7.0.0 <= 7.0.9
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
7.2.0 <= 7.2.11
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
7.3.0 <= 7.3.1.2
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
7.4.0 <= 7.4.7
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
7.6.0 <= 7.6.5
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
7.7.0 <= 7.7.12
Cisco Secure_Firewall_Management_Center
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
10.0.0 <= 10.0.1