EXPOSURES › CVE-2026-20316
CVE-2026-20316
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.
Cisco Secure Firewall Management Center (FMC) shipped with a hardcoded password that enabled unauthenticated remote access to sensitive systems, bypassing standard authentication controls. This failure exposes DIB organizations to unauthorized data access and violates FedRAMP/NIST 800-171 requirements for secure configuration management. Organizations must immediately patch affected FMC instances and audit all Cisco-managed firewalls for similar vulnerabilities.
Shame score — Hardcoded credentials in a critical security management product represent a negligent design flaw that directly undermines security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |