Exploited Known exploited (KEV) Ransomware use CVE-2026-20316

A hard-coded password in a firewall management appliance - one of only two such entries in 1,687 (Cisco FMC, CVE-2026-20316)

Cisco Secure Firewall Management Center (FMC) Added to KEV Jul 29, 2026 Federal remediation due 2026-08-01

A use of hard-coded password vulnerability in Cisco Secure Firewall Management Center has been added to CISA's Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can log in with a low-privileged account.

Key facts

  • CVE IDCVE-2026-20316
  • Affected (vendor / product)Cisco Secure Firewall Management Center (FMC)
  • CWECWE-259
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-08-01 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A hard-coded password (CWE-259) lets an unauthenticated remote attacker log in with a low-privileged account.
  • A credential embedded in a product does not differ between environments, so once known it reaches widely.
  • The subject is an appliance centrally managing firewalls - the defending machinery itself as the way in.
  • Of the 1,687 KEV records this site holds as of 2026-09-02, only two include CWE-259.
  • Cisco products account for 96 records, second among 281 vendors to Microsoft at 386.
  • The due date is three days after addition; 86 of the 1,687 carry a three-day deadline.

1A password embedded in the product

A hard-coded password is a credential written into the product in advance. Because it is not something the user sets, it either cannot be changed or is operated without anyone realising it can be. Once it is known, every environment running that product opens with the same key.

A password the user setsA password embedded in the product
Different in every environmentThe same wherever the product runs
A leak stays within that environmentOnce known, it reaches widely
It can be changed or revokedIt cannot change until an update is applied

2The defending appliance as the way in

The subject is an appliance that centrally manages firewalls. A hole in the authentication of the machinery meant to defend carries weight for how defence is designed. A management appliance holds the configuration and state of many devices, so getting into it spreads differently from attacking firewalls one at a time.

KEV records held by this site1,687CISA catalog of exploited vulnerabilities
Records including a hard-coded password (CWE-259)2this is one of them
Records for Cisco products96second only to Microsoft at 386

CWE-259 appears in only two of the 1,687 records. Cisco products account for 96, second among 281 vendors to Microsoft's 386 - more products yield more records.

3Three days

The due date is three days after addition. Of the 1,687 records this site holds as of 2026-09-02, twenty-one days is most common at 1,025 while three days covers 86. Even with a low-privileged account, being inside a management appliance is where investigation and response begin.

Why it matters

Vulnerabilities in security products themselves exploit a practical weakness: they fall outside asset management. A management appliance holds the configuration of many devices, so the reach of an intrusion differs from that of any single device. Hard-coded credentials cannot be disabled operationally, making the update the only remedy - itself a reason to raise priority.

FAQ

What is a hard-coded password?
A credential written into the product in advance. Because the user does not set it, it cannot be changed until an update is applied.
Is a low-privileged account less serious?
According to CISA it allows access to sensitive data within the impacted systems. Being inside a management appliance is itself where investigation and response begin.
What is the deadline?
It was added to KEV on 29 July 2026 with a due date of 1 August 2026. Verify applicability with official vendor information and your own environment.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#CISA#Cisco#firewall#hard-coded password#CWE-259
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.