Cisco Secure Firewall Management Center (FMC) Software is affected by a static credential vulnerability that could allow an unauthenticated remote attacker to log in using a low-privileged account and access sensitive data. The vulnerability, tracked as CVE-2026-20316, exists because static user credentials are present for a low-privileged account. Successful exploitation could provide access to information available to that account and may be combined with other vulnerabilities to elevate privileges. The vulnerability has a CVSS score of 5.3 (Medium) with the vector. It affects Cisco Secure FMC Software releases 7.0 and earlier, 7.2, 7.4, 7.6, 7.7, 10.0, and 10.1. The vulnerability affects Secure FMC Software regardless of device configuration, while Cloud-Delivered FMC, FDM, ASA, FTD, and Security Cloud Control are confirmed not affected. Cisco has also reported active exploitation of this vulnerability.
We recommend you to update Cisco Secure Firewall Management Center Software to version 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, 10.1.0.[/subscribe_to_unlock_form]
Cisco Secure Firewall Management Center (FMC) Software is affected by a static credential vulnerability that could allow an unauthenticated remote attacker to log in using a low-privileged account and access sensitive data. The vulnerability, tracked as CVE-2026-20316, exists because static user credentials are present for a low-privileged account. Successful exploitation could provide access to information available to that account and may be combined with other vulnerabilities to elevate privileges. The vulnerability has a CVSS score of 5.3 (Medium) with the vector. It affects Cisco Secure FMC Software releases 7.0 and earlier, 7.2, 7.4, 7.6, 7.7, 10.0, and 10.1. The vulnerability affects Secure FMC Software regardless of device configuration, while Cloud-Delivered FMC, FDM, ASA, FTD, and Security Cloud Control are confirmed not affected. Cisco has also reported active exploitation of this vulnerability.
We recommend you to update Cisco Secure Firewall Management Center Software to version 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, 10.1.0.[emaillocker id="1283"]
The following reports contain further technical details: