Threat reportVulnerabilityTL-2026-1759
CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV
CVE-2026-20316 (TL-2026-1759), also tracked as Cisco Secure Firewall Management Center Static Credential Vulnerability, is a critical-severity software vulnerability scored CVSS 5.3, first published 2026-07-29 and last reviewed 2026-09-14. It is attributed to Sandworm (Russia) with medium confidence, affects Cisco Secure Firewall Management Center (FMC) Software — on-premises, references 3 CVEs (CVE-2026-20316, CVE-2026-20079, CVE-2026-20131), maps to 74 MITRE ATT&CK techniques (T1003, T1005, T1007), and is covered by 9 detection rules and 135 indicators of compromise.
- CVSS
- 5.3/10Critical
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 74MITRE ATT&CK
- Actors
- 1Sandworm
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 135Indicators of compromise
Key facts for TL-2026-1759
- Threat ID
- TL-2026-1759
- Also known as
- Cisco Secure Firewall Management Center Static Credential Vulnerability, cisco-sa-fmc-static-cred-BET3Cjh
- Severity
- CRITICAL
- CVSS
- 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Sandworm
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- UNKNOWN
- Target sectors
- government administration, critical-infrastructure, technology, education, engineering, manufacturing, health
- Target regions
- united states of america, Global
- Detection rules
- 9
- Indicators of compromise
- 135
- Updates
- 2026-09-14 · 10 updates · revalidated 10× · latest source
Malware and tooling in CVE-2026-20316
Malware and tooling: interlock, Certify, Cisco Software Checker, ConnectWise ScreenConnect, HAProxy, Volatility Framework
How CVE-2026-20316 works
CISA added CVE-2026-20316, a Cisco Secure Firewall Management Center (FMC) Use of Hard-coded Password vulnerability (CWE-259), to its Known Exploited Vulnerabilities Catalog on 2026-07-29 after confirming active exploitation. Static credentials for a low-privileged account allow an unauthenticated remote attacker to log in to the FMC web management interface and access sensitive data; Cisco warns the flaw can be combined with other vulnerabilities to escalate privileges. Federal agencies must remediate by 2026-08-01.
CVE-2026-20316 is a Use of Hard-coded Password vulnerability (CWE-259) in Cisco Secure Firewall Management Center (FMC) Software, disclosed by Cisco on 2026-07-29 in security advisory cisco-sa-fmc-static-cred-BET3Cjh (bug ID CSCwt95997, reported by Jimi Sebree of Horizon3.ai). The root cause is the presence of static user credentials tied to a low-privileged account baked into the FMC software image. Because these credentials are identical across deployments and require no prior access, an unauthenticated, remote attacker who reaches the FMC web management interface over the network can authenticate directly as that account and retrieve sensitive data from the affected system without ever needing valid administrator credentials.
Cisco's CVSS 3.1 base score for this issue is 5.3 (Medium; AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N — network-exploitable, low complexity, no privileges or user interaction required, confidentiality-only impact), but the advisory assigns it a qualitative High impact rating because a foothold gained through the static account can be chained with other FMC vulnerabilities to escalate privileges to full administrative control. This chaining risk is consistent with FMC's disclosure history: on 2026-03-04, Cisco separately patched two unrelated maximum-severity (CVSS 10.0) FMC flaws in the same product line — CVE-2026-20079 (authentication bypass caused by an improperly configured boot-time process, allowing unauthenticated remote attackers to send crafted HTTP requests, bypass authentication, execute script files, and obtain root-level OS access; CWE-288, Snort SIDs 66075-66080 provide detection coverage) and CVE-2026-20131 (unsafe deserialization of a user-supplied Java byte stream on the FMC web interface, allowing an unauthenticated attacker to execute arbitrary Java code as root). Cisco's advisory for CVE-2026-20316 does not claim direct technical chaining with those two specific CVEs, but the pattern illustrates why CISA and Cisco treat any unauthenticated-access primitive on FMC as high-risk: FMC is the centralized management plane for Cisco Secure Firewall/Firepower Threat Defense sensors, so compromise of the management platform has a blast radius extending to every firewall it manages (CVSS Scope: Changed in the companion 2026-03 advisories).
The chaining risk cited in Cisco's advisory is not hypothetical: CVE-2026-20131, one of the two related maximum-severity FMC flaws from the 2026-03-04 disclosure, was independently confirmed to have been exploited as a zero-day by the Interlock ransomware group beginning 2026-01-26 — roughly 36 days before Cisco's public disclosure on 2026-03-18/19. Interlock's post-exploitation toolkit against compromised FMC hosts (per AWS/Amazon and eSentire research) included a PowerShell reconnaissance script enumerating OS/hardware details, running services, Hyper-V inventory, browser artifacts (Chrome, Edge, Firefox, IE, 360), active network connections, and RDP authentication events; a self-updating/self-deleting JavaScript remote access trojan; a Java implant maintaining redundant C2 channels; a memory-resident web shell for encrypted command execution; a lightweight network beacon confirming successful compromise; ConnectWise ScreenConnect for persistent legitimate-tool remote access; the Certify tool to abuse Active Directory Certificate Services misconfigurations for privilege escalation and lateral movement; the Volatility Framework for memory forensics and credential extraction; and HAProxy configured on compromised Linux hosts as a reverse proxy for infrastructure laundering — consistent with Interlock's established double-extortion ransomware model (data exfiltration followed by encryption, embedded ransom notes, and Tor-based negotiation portals, with operator activity clustering in the UTC+3 timezone). CISA added CVE-2026-20131 to the KEV Catalog on 2026-03-19 with a 2026-03-22 federal remediation deadline. This confirmed ransomware exploitation of a sibling FMC vulnerability underscores why CISA and Cisco treat CVE-2026-20316's unauthenticated-access primitive as high-risk even at a Medium CVSS score: the FMC management plane is an established ransomware entry point.
CISA added CVE-2026-20316 itself to the Known Exploited Vulnerabilities (KEV) Catalog on 2026-07-29, confirming active exploitation in the wild, and set a remediation due date of 2026-08-01 for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive 26-04 (Prioritizing Security Updates Based on Risk, effective 2026-06-10), which requires vulnerabilities meeting KEV/exploitation/impact criteria to be remediated within days of catalog addition and mandates forensic triage of potentially-already-compromised systems. No workarounds exist; Cisco has published hotfixes for every affected on-premises release train (7.0: GB-7.0.9.1-3; 7.2: HL-7.2.11.1-4; 7.4: HG-7.4.7.1-3; 7.6: CY-7.6.5.1-2; 7.7: AM-7.7.12.1-2; 10.0: P-10.0.1.1-2). NVD's own CVE-2026-20316 record additionally lists FMC 7.3.0 through 7.3.1.2 as a vulnerable range, which does not appear in Cisco's hotfix table — implying that branch has no dedicated in-place hotfix and requires upgrading to a fixed release train instead. Cloud-Delivered FMC, Firepower/Firewall Device Manager, standalone ASA Software, standalone FTD Software, and Security Cloud Control are not affected. Beyond applying the hotfix, Cisco recommends immediate rotation of credentials on affected devices, since the static account itself does not change merely by patching the software defect that exposed it, as a general hygiene precaution. Cisco's own risk note observes that if the FMC management interface has no public internet access, the attack surface for CVE-2026-20316 is reduced — reinforcing the standing recommendation to keep management planes off the public internet.
MITRE ATT&CK techniques used in TL-2026-1759
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1649 Steal or Forge Authentication Certificates
Collection
T1005 Data from Local System; T1040 Network Sniffing; T1119 Automated Collection; T1213 Data from Information Repositories; T1560 Archive Collected Data
Discovery
T1007 System Service Discovery; T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1087.002 Account Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1071.004 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573 Encrypted Channel
Lateral Movement
T1021 Remote Services; T1021.004 Remote Services; T1021.006 Remote Services; T1210 Exploitation of Remote Services; T1550.002 Use Alternate Authentication Material; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.004 Masquerading; T1036.005 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1562.001 Impair Defenses
Exfiltration
T1029 Scheduled Transfer; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1037.004 Boot or Logon Initialization Scripts; T1136 Create Account; T1505 Server Software Component; T1505.003 Server Software Component
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Initial Access
T1078 Valid Accounts; T1078.001 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
command-and-control
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft
credential-access
T1539 Steal Web Session Cookie
lateral-movement
T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1595 Active Scanning; T1595.002 Active Scanning; T1596 Search Open Technical Databases
defense-impairment
Affected products and versions in CVE-2026-20316
- Cisco — Secure Firewall Management Center (FMC) Software — on-premises
Vulnerable versions: 7.0 (prior to hotfix GB-7.0.9.1-3); 7.2 (prior to hotfix HL-7.2.11.1-4); 7.4 (prior to hotfix HG-7.4.7.1-3); 7.6 (prior to hotfix CY-7.6.5.1-2); 7.7 (prior to hotfix AM-7.7.12.1-2); 10.0 (prior to hotfix P-10.0.1.1-2)
Fixed in: 7.0 with hotfix GB-7.0.9.1-3; 7.2 with hotfix HL-7.2.11.1-4; 7.4 with hotfix HG-7.4.7.1-3; 7.6 with hotfix CY-7.6.5.1-2; 7.7 with hotfix AM-7.7.12.1-2; 10.0 with hotfix P-10.0.1.1-2 - Cisco — Secure Firewall Management Center (FMC) Software — 7.3 branch
Vulnerable versions: 7.3.0 - 7.3.1.2
Fixed in: No dedicated 7.3 hotfix is listed in Cisco's advisory; NVD lists this range as vulnerable, so upgrade to a fixed release train (e.g., 7.4 with hotfix HG-7.4.7.1-3) is recommended - Cisco — Cloud-Delivered Firewall Management Center, Firewall Device Manager, ASA Software, FTD Software, Security Cloud Control
Fixed in: Not affected by CVE-2026-20316
Remediation for CVE-2026-20316
Patches
- FMC 7.0 -> hotfix GB-7.0.9.1-3
- FMC 7.2 -> hotfix HL-7.2.11.1-4
- FMC 7.4 -> hotfix HG-7.4.7.1-3
- FMC 7.6 -> hotfix CY-7.6.5.1-2
- FMC 7.7 -> hotfix AM-7.7.12.1-2
- FMC 10.0 -> hotfix P-10.0.1.1-2
Immediate actions
- Apply the Cisco-published hotfix for your FMC release train (GB-7.0.9.1-3, HL-7.2.11.1-4, HG-7.4.7.1-3, CY-7.6.5.1-2, AM-7.7.12.1-2, or P-10.0.1.1-2)
- Restrict network access to the FMC web management interface to trusted management networks / VPN only; do not expose the FMC web UI to the public internet
- Rotate credentials on all affected on-premises FMC devices immediately, as recommended by Cisco
- Federal agencies: remediate by the CISA KEV due date of 2026-08-01 per BOD 26-04
- FMC 7.3.x deployments (listed as vulnerable by NVD but without a dedicated 7.3 hotfix in Cisco's advisory) should be upgraded to a fixed release train (e.g., 7.4 with hotfix HG-7.4.7.1-3) rather than waiting on an in-place 7.3 patch
Workarounds
- None available — Cisco's advisory states there are no workarounds; the hotfix must be applied
Longer-term hardening
- Perform forensic triage per BOD 26-04 guidance to determine whether affected FMC systems were already accessed via the static account prior to patching
- Inventory all Cisco Secure Firewall Management Center deployments and track patch/hotfix compliance centrally
- Monitor authentication logs on FMC for logins from the disclosed low-privileged static account
- Segment and firewall management-plane access (FMC, FDM) away from general enterprise/internet-facing networks
- Given confirmed Interlock ransomware exploitation of a sibling FMC vulnerability (CVE-2026-20131), treat any FMC compromise as a potential ransomware precursor: hunt for ScreenConnect, Certify, Volatility, and HAProxy artifacts, unexpected webshells, and outbound beacon traffic
CVEs associated with CVE-2026-20316
Weaknesses (CWE) in CVE-2026-20316
Timeline of CVE-2026-20316
Showing the 20 most recent tracked events.
- CISA issues Binding Operational Directive 26-04, 'Prioritizing Security Updates Based on Risk,' requiring FCEB agencies to remediate high-risk exploited vulnerabilities on an accelerated, risk-based timeline and to perform forensic triage of potentially compromised systems.
- Cisco PSIRT becomes aware of active in-the-wild exploitation of the static-credential flaw later designated CVE-2026-20316.
- Earliest precisely timestamped exploitation log entry surfaces (via BleepingComputer, sourced from Cisco): a sudo www->root package_info.pl /var/tmp/license.tmp --lsm entry on host 'firepower', confirming in-the-wild exploitation six days before Cisco's public advisory.
- CISA publishes the alert 'CISA Adds One Known Exploited Vulnerability to Catalog' announcing the CVE-2026-20316 KEV addition.
- CISA adds CVE-2026-20316 to the Known Exploited Vulnerabilities Catalog, confirming active exploitation of the static-credential flaw in the wild.
- CVE-2026-20316 is published to the National Vulnerability Database with CVSS 3.1 base score 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), CWE-259 classification, and an additional vulnerable-version range (FMC 7.3.0-7.3.1.2) not present in Cisco's hotfix table.
- Cisco publishes security advisory cisco-sa-fmc-static-cred-BET3Cjh disclosing CVE-2026-20316, a Use of Hard-coded Password vulnerability (CWE-259) in Secure Firewall Management Center, along with hotfixes for all affected release trains.
- Cisco credits Jimi Sebree of Horizon3.ai (Cisco Bug ID CSCwt95997) as the reporter of the static-credential flaw in Secure Firewall Management Center.
- Horizon3.ai releases a NodeZero Rapid Response test for CVE-2026-20316, letting organizations safely verify whether their FMC appliances are vulnerable, per the newer report.
- HKCERT publishes its own security bulletin on the Cisco Secure FMC information-disclosure vulnerability.
- Cisco finalizes advisory cisco-sa-fmc-static-cred-BET3Cjh at version 1.2 (Final).
- Sophos Counter Threat Unit identifies a new 64-bit x86-64 Linux port of Cyclops Blink (binary 'timezonecheck') on compromised Cisco FMC appliances — the first observed port of the malware beyond its original PowerPC/WatchGuard codebase.
- CISA's ADP SSVC decision for CVE-2026-20316 is finalized as exploitation=active, automatable=yes, technicalImpact=partial, underpinning the BOD 26-04 remediation deadline, per the newer report.
- Federal Civilian Executive Branch agencies' CISA-mandated deadline to remediate CVE-2026-20316 per the KEV Catalog entry and BOD 26-04 guidance.
- CISA publishes a follow-up public news alert reiterating the CVE-2026-20316 KEV Catalog addition, active-exploitation status, and no-workaround constraint, per the newer report.
- Cisco PSIRT becomes aware that CVE-2026-20079 is being actively exploited in the wild (Cisco discloses only the month, 'August 2026').
- Cisco Talos publishes 'Active exploitation of Cisco Secure Firewall Management Center vulnerabilities,' detailing three post-compromise clusters (UAT-11823/Sandworm-overlap deploying Cyclops Blink, UAT-11988/Qilin-affiliate using CVE-2026-20316 static credentials, and UAT-12197 web-shell crimeware) and releasing IOCs and Snort signatures.
- Cisco publicly confirms active exploitation of CVE-2026-20079; CISA adds it to the KEV catalog with a Federal remediation deadline of 2026-09-12.
- CISA's Federal Civilian Executive Branch remediation deadline for CVE-2026-20079 arrives.
- Cisco plans a comprehensive FMC hardening release with additional hotfixes and vulnerability patches for the week of 2026-09-14 to 2026-09-16.
Update history for TL-2026-1759
- 2026-09-14 — Cyclops Blink Evolves Into x86-64 Linux Implant Targeting Cisco Firewall Management Center (CVE-2026-20079, CVE-2026-20316): What changed No escalation to severity/exploitability/status (already CRITICAL/ACTIVE/ACTIVE) or attribution_confidence (already MEDIUM). The report's CVSS 10.0 figure belongs to the already-known CVE-2026-20079, not this record's flagship
- 2026-09-11 — CVE-2026-20079: Cisco Secure FMC Authentication Bypass Actively Exploited by Sandworm and Qilin Ransomware Affiliate: What changed CVE-2026-20079 — already tracked in this threat's cve_list as a related maximum-severity (CVSS 10.0) FMC auth-bypass flaw — is now confirmed actively exploited in the wild. Cisco Talos's 2026-09-09 report attributes the activit
- 2026-08-03 — CVE-2026-20316 — Cisco Secure Firewall Management Center Hard-Coded Static Credential Vulnerability Under Active Exploitation (Chained with CVE-2026-20079/CVE-2026-20131 for Root Access): What changed No severity/exploitability/status escalation accepted. The newer report proposes severity CRITICAL→HIGH (a downgrade — rejected) and cvss_score 5.3→8.9, but the 8.9 figure conflates Cisco's qualitative Security Impact Rating wi
- 2026-08-02 — Cisco Secure Firewall Management Center Static Credential Vulnerability Actively Exploited (CVE-2026-20316): What changed No severity/exploitability/status/attribution change — remains CRITICAL/ACTIVE/Unattributed. Update is additive detail only: one new detection signature and three new dated events. New indicators (1) 1 new IOC: Snort Rule 66883
- 2026-08-01 — Cisco Secure FMC Static-Credential Zero-Day (CVE-2026-20316) Exploited in the Wild: What changed No field escalation. Severity/exploitability/status/CVSS/attribution unchanged (the newer report's 'HIGH' severity label is a downgrade from the existing CRITICAL and is not applied). New indicators (2) 2 new hard-coded machine
- 2026-07-31 — CVE-2026-20316: Cisco Secure FMC Static Credential Vulnerability Actively Exploited, Added to CISA KEV: What changed No field-level escalation — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (5.3), and attribution (LOW/Unknown) all match the existing record. The update adds concrete network-level Interlock infrastructure
- 2026-07-31 — CVE-2026-20316: Cisco Secure FMC Static Credential Vulnerability Actively Exploited: What changed No change to severity/exploitability/status — the record is already at CRITICAL/ACTIVE/ACTIVE, the maximum evidenced state. The trigger report's severity_level of HIGH is a downgrade relative to the existing CRITICAL and was di
- 2026-07-30 — Cisco Secure Firewall Management Center Hard-Coded Credential 0-Day Actively Exploited (CVE-2026-20316): What changed No field escalations warranted: CVSS score, exploitability (ACTIVE), status (ACTIVE), and attribution confidence (LOW) are unchanged. The newer report's own severity_level of HIGH is a downgrade from the existing CRITICAL and i
- 2026-07-30 — Cisco Secure Firewall Management Center Static Credential / Information Disclosure Vulnerability (CVE-2026-20316) — CISA KEV, Actively Exploited: What changed No whitelisted field requires escalation — severity (CRITICAL), exploitability (ACTIVE), and status (ACTIVE) were already at their maximum values in the existing record. The update deepens the intelligence picture: exploitation
- 2026-07-29 — CVE-2026-20316: Cisco Secure Firewall Management Center Static Credential Flaw Exploited in Zero-Day Attacks: What changed No field escalations — severity/exploitability/status/CVSS/attribution are unchanged (the newer report's own 'HIGH' severity label is a downgrade from the existing CRITICAL and was ignored per the no-downgrade rule). New indica
Sources cited for CVE-2026-20316
- CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Known Exploited Vulnerabilities Catalog (data feed)
- CISA Known Exploited Vulnerabilities Catalog
- Cisco Security Advisory: Cisco Secure Firewall Management Center Software Static Credential Vulnerability
- NVD - CVE-2026-20316 Detail
- BOD 26-04: Prioritizing Security Updates Based on Risk
- Critical Vulnerabilities in Cisco Secure Firewall Management Center
- Cisco fixes maximum-severity Secure FMC bugs threatening firewall security
- Critical Cisco Vulnerabilities: CVE-2026-20079 and CVE-2026-20131 Affecting Cisco Secure Firewall Management Center
- Cisco Patches Secure Firewall Management Center Software Vulnerabilities (CVE-2026-20079 & CVE-2026-20131)
- Exploited This Week: New CISA KEV Additions (July 2026)
- CVE-2026-20131: Cisco FMC RCE Vulnerability
- CVE-2026-20079: Cisco FMC Auth Bypass
- Cisco Secure Firewall Management Center - Security Advisories, Responses and Notices
- Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
Detection coverage for TL-2026-1759
As of 2026-09-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1759 across Splunk SPL, Microsoft KQL and Sigma, covering 135 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.