Description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. 
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  
Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Published: 2026-07-29
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the web interface of Cisco Secure Firewall Management Center (FMC). It allows an unauthenticated remote attacker to log in using static, low‑privileged account credentials, thereby gaining access to the system with the permissions of that user. This can enable viewing and potential exfiltration of sensitive data. The weakness is a hard‑coded or otherwise unchangeable password stored within the product and corresponds to CWE‑259.

Affected Systems

The affected product is Cisco Secure Firewall Management Center (FMC). No specific version range is listed, so all deployed instances are potentially vulnerable until a patch removes the static credentials.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, yet the vulnerability is listed in the CISA KEV catalog, signaling real‑world exploitation. The EPSS score of <1% suggests few public exploitation opportunities, but the high Security Impact Rating reflects the flaw’s potential to combine with other FMC vulnerabilities for privilege escalation. Based on the description, it is inferred that the likely attack vector requires external exposure of the FMC web interface; attackers would need network access to the management console and then attempt the static credentials. Successful exploitation would permit a login as the low‑privileged user and could serve as a foothold for further compromise.

Generated by OpenCVE AI on August 2, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Firewall Management Center patch or upgrade to a version where static low‑privileged credentials have been removed.
  • If a patch is not yet available, change or disable the default low‑privileged account credentials immediately.
  • Restrict external access to the FMC management web interface by placing it behind a firewall or VPN and limiting allowed IP addresses to trusted administrators.
  • Monitor authentication logs for unexpected low‑privileged login attempts and investigate promptly.

Generated by OpenCVE AI on August 2, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-29T00:00:00+00:00', 'dueDate': '2026-08-01T00:00:00+00:00'}


Wed, 29 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp; Note:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp; Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Title Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Weaknesses CWE-259
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-01T03:55:31.477Z

Reserved: 2025-10-08T11:59:15.410Z

Link: CVE-2026-20316

cve-icon Vulnrichment

Updated: 2026-07-29T16:42:19.065Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T17:16:51.840

Modified: 2026-08-01T05:16:55.973

Link: CVE-2026-20316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password