# CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV

> CISA added CVE-2026-20316, a Cisco Secure Firewall Management Center (FMC) Use of Hard-coded Password vulnerability (CWE-259), to its Known Exploited Vulnerabilities Catalog on 2026-07-29 after confirming active exploitation. Static credentials for a low-privileged account allow an unauthenticated remote attacker to log in to the FMC web management interface and access sensitive data; Cisco warns the flaw can be combined with other vulnerabilities to escalate privileges. Federal agencies must remediate by 2026-08-01.

- **Published:** 2026-07-29T00:00:00Z
- **Last reviewed:** 2026-09-14T13:45:13.502Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1759
- **ID:** TL-2026-1759
- **Severity:** CRITICAL (CVSS 5.3)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Sandworm (Russia)
- **Detections:** 9 · **IOCs:** 135 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20316, CVE-2026-20079, CVE-2026-20131

## Description

CVE-2026-20316 is a Use of Hard-coded Password vulnerability (CWE-259) in Cisco Secure Firewall Management Center (FMC) Software, disclosed by Cisco on 2026-07-29 in security advisory cisco-sa-fmc-static-cred-BET3Cjh (bug ID CSCwt95997, reported by Jimi Sebree of Horizon3.ai). The root cause is the presence of static user credentials tied to a low-privileged account baked into the FMC software image. Because these credentials are identical across deployments and require no prior access, an unauthenticated, remote attacker who reaches the FMC web management interface over the network can authenticate directly as that account and retrieve sensitive data from the affected system without ever needing valid administrator credentials.

Cisco's CVSS 3.1 base score for this issue is 5.3 (Medium; AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N — network-exploitable, low complexity, no privileges or user interaction required, confidentiality-only impact), but the advisory assigns it a qualitative High impact rating because a foothold gained through the static account can be chained with other FMC vulnerabilities to escalate privileges to full administrative control. This chaining risk is consistent with FMC's disclosure history: on 2026-03-04, Cisco separately patched two unrelated maximum-severity (CVSS 10.0) FMC flaws in the same product line — CVE-2026-20079 (authentication bypass caused by an improperly configured boot-time process, allowing unauthenticated remote attackers to send crafted HTTP requests, bypass authentication, execute script files, and obtain root-level OS access; CWE-288, Snort SIDs 66075-66080 provide detection coverage) and CVE-2026-20131 (unsafe deserialization of a user-supplied Java byte stream on the FMC web interface, allowing an unauthenticated attacker to execute arbitrary Java code as root). Cisco's advisory for CVE-2026-20316 does not claim direct technical chaining with those two specific CVEs, but the pattern illustrates why CISA and Cisco treat any unauthenticated-access primitive on FMC as high-risk: FMC is the centralized management plane for Cisco Secure Firewall/Firepower Threat Defense sensors, so compromise of the management platform has a blast radius extending to every firewall it manages (CVSS Scope: Changed in the companion 2026-03 advisories).

The chaining risk cited in Cisco's advisory is not hypothetical: CVE-2026-20131, one of the two related maximum-severity FMC flaws from the 2026-03-04 disclosure, was independently confirmed to have been exploited as a zero-day by the Interlock ransomware group beginning 2026-01-26 — roughly 36 days before Cisco's public disclosure on 2026-03-18/19. Interlock's post-exploitation toolkit against compromised FMC hosts (per AWS/Amazon and eSentire research) included a PowerShell reconnaissance script enumerating OS/hardware details, running services, Hyper-V inventory, browser artifacts (Chrome, Edge, Firefox, IE, 360), active network connections, and RDP authentication events; a self-updating/self-deleting JavaScript remote access trojan; a Java implant maintaining redundant C2 channels; a memory-resident web shell for encrypted command execution; a lightweight network beacon confirming successful compromise; ConnectWise ScreenConnect for persistent legitimate-tool remote access; the Certify tool to abuse Active Directory Certificate Services misconfigurations for privilege escalation and lateral movement; the Volatility Framework for memory forensics and credential extraction; and HAProxy configured on compromised Linux hosts as a reverse proxy for infrastructure laundering — consistent with Interlock's established double-extortion ransomware model (data exfiltration followed by encryption, embedded ransom notes, and Tor-based negotiation portals, with operator activity clustering in the UTC+3 timezone). CISA added CVE-2026-20131 to the KEV Catalog on 2026-03-19 with a 2026-03-22 federal remediation deadline. This confirmed ransomware exploitation of a sibling FMC vulnerability underscores why CISA and Cisco treat CVE-2026-20316's unauthenticated-access primitive as high-risk even at a Medium CVSS score: the FMC management plane is an established ransomware entry point.

CISA added CVE-2026-20316 itself to the Known Exploited Vulnerabilities (KEV) Catalog on 2026-07-29, confirming active exploitation in the wild, and set a remediation due date of 2026-08-01 for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive 26-04 (Prioritizing Security Updates Based on Risk, effective 2026-06-10), which requires vulnerabilities meeting KEV/exploitation/impact criteria to be remediated within days of catalog addition and mandates forensic triage of potentially-already-compromised systems. No workarounds exist; Cisco has published hotfixes for every affected on-premises release train (7.0: GB-7.0.9.1-3; 7.2: HL-7.2.11.1-4; 7.4: HG-7.4.7.1-3; 7.6: CY-7.6.5.1-2; 7.7: AM-7.7.12.1-2; 10.0: P-10.0.1.1-2). NVD's own CVE-2026-20316 record additionally lists FMC 7.3.0 through 7.3.1.2 as a vulnerable range, which does not appear in Cisco's hotfix table — implying that branch has no dedicated in-place hotfix and requires upgrading to a fixed release train instead. Cloud-Delivered FMC, Firepower/Firewall Device Manager, standalone ASA Software, standalone FTD Software, and Security Cloud Control are not affected. Beyond applying the hotfix, Cisco recommends immediate rotation of credentials on affected devices, since the static account itself does not change merely by patching the software defect that exposed it, as a general hygiene precaution. Cisco's own risk note observes that if the FMC management interface has no public internet access, the attack surface for CVE-2026-20316 is reduced — reinforcing the standing recommendation to keep management planes off the public internet.

## MITRE ATT&CK

- T1595 Active Scanning
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1219 Remote Access Tools
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1070 Indicator Removal
- T1552 Unsecured Credentials
- T1003 OS Credential Dumping
- T1649 Steal or Forge Authentication Certificates
- T1087 Account Discovery
- T1082 System Information Discovery
- T1049 System Network Connections Discovery
- T1007 System Service Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1596 Search Open Technical Databases
- T1587 Develop Capabilities
- T1550 Use Alternate Authentication Material
- T1518 Software Discovery
- T1133 External Remote Services
- T1136 Create Account
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1057 Process Discovery
- T1217 Browser Information Discovery
- T1021 Remote Services
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1583 Acquire Infrastructure
- T1016 System Network Configuration Discovery

## Sources

- [CISA Adds One Known Exploited Vulnerability to Catalog](https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog)
- [CISA Known Exploited Vulnerabilities Catalog (data feed)](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Cisco Security Advisory: Cisco Secure Firewall Management Center Software Static Credential Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh)
- [NVD - CVE-2026-20316 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-20316)
- [BOD 26-04: Prioritizing Security Updates Based on Risk](https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk)
- [Critical Vulnerabilities in Cisco Secure Firewall Management Center](https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-021/)
- [Cisco fixes maximum-severity Secure FMC bugs threatening firewall security](https://securityaffairs.com/188921/security/cisco-fixes-maximum-severity-secure-fmc-bugs-threatening-firewall-security.html)
- [Critical Cisco Vulnerabilities: CVE-2026-20079 and CVE-2026-20131 Affecting Cisco Secure Firewall Management Center](https://www.abstract.security/blog/critical-cisco-vulnerabilities-cve-2026-20079-and-cve-2026-20131)
- [Cisco Patches Secure Firewall Management Center Software Vulnerabilities (CVE-2026-20079 & CVE-2026-20131)](https://threatprotect.qualys.com/2026/03/05/cisco-patches-secure-firewall-management-center-software-vulnerabilities-cve-2026-20079-cve-2026-20131/)
- [Exploited This Week: New CISA KEV Additions (July 2026)](https://senserva.com/exploited-this-week.html)
- [CVE-2026-20131: Cisco FMC RCE Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20131/)
- [CVE-2026-20079: Cisco FMC Auth Bypass](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20079/)
- [Cisco Secure Firewall Management Center - Security Advisories, Responses and Notices](https://www.cisco.com/c/en/us/support/security/defense-center/products-security-advisories-list.html)
- [Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access](https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1759
