Advisory 176: Cisco Secure Firewall Management Center (FMC) Static Credential Vulnerability (CVE-2026-20316)
Release Date: 29th July 2026
Impact : HIGH / CRITICAL
TLP Rating: Clear 
The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-20316 is a vulnerability in Cisco Secure Firewall Management Center (FMC) Software (CWE-259, Use of Hard-coded Password; CVSS v3.1 base score 5.3, Medium) caused by the presence of static user credentials for a low-privileged account in the FMC web-based management interface. Although the CVSS base score is Medium, Cisco has assigned this vulnerability a Security Impact Rating (SIR) of High, because the low-privileged access it grants can be combined with other Cisco Secure Firewall Management Center vulnerabilities to elevate privileges. Cisco has confirmed active exploitation of this vulnerability in the wild.
What are the systems affected?
The following on-premises product is affected:
- Cisco Secure Firewall Management Center (FMC) Software
Affected release branches (hot fixes released by Cisco):
- FMC Software 7.0 release branch
- FMC Software 7.2 release branch
- FMC Software 7.4 release branch
- FMC Software 7.6 release branch
- FMC Software 7.7 release branch
- FMC Software 10.0 release branch
Cloud-Delivered FMC, Firewall Device Manager (FDM), Secure Firewall ASA Software, Secure Firewall Threat Defense (FTD) Software, and Security Cloud Control are not affected by this vulnerability.
What does this mean?
Typical exploitation flow:
- Remote unauthenticated login
- An attacker uses the static, hard-coded low-privileged account credentials to log in remotely to the FMC web-based management interface without needing any valid credentials of their own.
- Access to sensitive data
- A successful login allows the attacker to access sensitive data accessible to that low-privileged account.
- Potential privilege escalation
- Cisco advises this access can be combined with other Cisco Secure FMC vulnerabilities, including CVE-2026-20079 (a separate critical authentication bypass updated in the same advisory cycle), to obtain greater control, potentially up to root access.
- Reduced exposure for internal-only deployments
- If the FMC management interface does not have public internet access, the attack surface associated with this vulnerability is reduced.
This vulnerability requires:
- No authentication
- No user interaction
- Low attack complexity
Mitigation process?
CERTVU recommends the following:
- Apply Security Updates Immediately
- Install the Cisco-released hot fix appropriate to your FMC release branch (7.0, 7.2, 7.4, 7.6, 7.7, or 10.0) without delay.
- Restrict Network Exposure
- Restrict access to the FMC web-based management interface to trusted administrative networks only, as an interim defense-in-depth control pending patching.
- If your VCO is on an end-of-support release, contact Arista TAC to discuss upgrade options, as end-of-support versions have not been assessed for this issue.
- Review for Prior Compromise
- Review FMC logs for the /var/tmp/license.tmp indicator and any unexpected low-privilege logins, and treat any positive finding as a potential compromise requiring incident response.
- Monitor Related Advisories
- Track Cisco's updated advisory for CVE-2026-20079 given the overlapping forensic indicator and potential for chained exploitation.
Reference
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316
- https://www.cve.org/CVERecord?id=CVE-2026-20316
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- https://cwe.mitre.org/data/definitions/259.html
- Download advisory (English): Cisco Secure Firewall Management Center (FMC) Static Credential Vulnerability (CVE-2026-20316)