A hard-coded password in a firewall management appliance - one of only two such entries in 1,687 (Cisco FMC, CVE-2026-20316)
A use of hard-coded password vulnerability in Cisco Secure Firewall Management Center has been added to CISA's Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can log in with a low-privileged account.
Key facts
- CVE IDCVE-2026-20316
- Affected (vendor / product)Cisco Secure Firewall Management Center (FMC)
- CWECWE-259
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-08-01 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A hard-coded password (CWE-259) lets an unauthenticated remote attacker log in with a low-privileged account.
- A credential embedded in a product does not differ between environments, so once known it reaches widely.
- The subject is an appliance centrally managing firewalls - the defending machinery itself as the way in.
- Of the 1,687 KEV records this site holds as of 2026-09-02, only two include CWE-259.
- Cisco products account for 96 records, second among 281 vendors to Microsoft at 386.
- The due date is three days after addition; 86 of the 1,687 carry a three-day deadline.
1A password embedded in the product
A hard-coded password is a credential written into the product in advance. Because it is not something the user sets, it either cannot be changed or is operated without anyone realising it can be. Once it is known, every environment running that product opens with the same key.
2The defending appliance as the way in
The subject is an appliance that centrally manages firewalls. A hole in the authentication of the machinery meant to defend carries weight for how defence is designed. A management appliance holds the configuration and state of many devices, so getting into it spreads differently from attacking firewalls one at a time.
CWE-259 appears in only two of the 1,687 records. Cisco products account for 96, second among 281 vendors to Microsoft's 386 - more products yield more records.
3Three days
The due date is three days after addition. Of the 1,687 records this site holds as of 2026-09-02, twenty-one days is most common at 1,025 while three days covers 86. Even with a low-privileged account, being inside a management appliance is where investigation and response begin.
Why it matters
Vulnerabilities in security products themselves exploit a practical weakness: they fall outside asset management. A management appliance holds the configuration of many devices, so the reach of an intrusion differs from that of any single device. Hard-coded credentials cannot be disabled operationally, making the update the only remedy - itself a reason to raise priority.
FAQ
What is a hard-coded password?
Is a low-privileged account less serious?
What is the deadline?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).