← All Advisories

CVE-2026-20316: Cisco Secure Firewall

Status: KEV  |  Advisory ID: CVE-2026-20316

Key Details

CVECVE-2026-20316
Affected productsCisco Secure Firewall Management Center (FMC)
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-259 (Use of Hard-coded Password)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-07-29.
Exploitation prediction (EPSS)11% probability of exploitation in the next 30 days (96% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-08-01 (CISA KEV, Binding Operational Directive).

What to Know

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20316