Skip to content
COOEY

EXPOSURES › CVE-2026-20316

CVE-2026-20316

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-20316 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wilddefault-credshardcoded-credssupply-chain

Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.

Cisco Secure Firewall Management Center (FMC) shipped with a hardcoded password that enabled unauthenticated remote access to sensitive systems, bypassing standard authentication controls. This failure exposes DIB organizations to unauthorized data access and violates FedRAMP/NIST 800-171 requirements for secure configuration management. Organizations must immediately patch affected FMC instances and audit all Cisco-managed firewalls for similar vulnerabilities.

Shame score — Hardcoded credentials in a critical security management product represent a negligent design flaw that directly undermines security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized