Decoding the world of cybersecurity

Exploited Cisco flaw exposes firewall management

Cisco says attackers are exploiting a static credential flaw in Secure Firewall Management Center and has urged customers to patch and rotate credentials, keys, and certificates.

Exploited Cisco flaw exposes firewall management
Summary
  • CVE-2026-20316 affects Cisco Secure Firewall Management Center Software and allows unauthenticated remote login with a low-privileged account.
  • Cisco says active exploitation has been ongoing and that no workarounds are available.
  • Firewall management compromise can affect segmentation, visibility, policy trust, and recovery confidence across enterprise networks.

Cisco has released fixes for an actively exploited vulnerability in Secure Firewall Management Center Software that could allow an unauthenticated remote attacker to log in to an affected device using static credentials.

The vulnerability, tracked as CVE-2026-20316, affects the web interface of Cisco Secure FMC Software. Cisco assigned the advisory a high security impact rating, despite a CVSS score of 5.3, because the low-privileged access can be used with other Secure FMC vulnerabilities to elevate privileges.

Successful exploitation allows an attacker to log in with a low-privileged account and access sensitive data on affected systems. Cisco said the vulnerability affects Secure FMC Software regardless of configuration, although the attack surface is reduced where the FMC management interface is not exposed to the public internet.

Cisco has provided a specific indicator for administrators to check. The company said exploitation may be visible in system logs through references to a temporary licence file path. If exploitation is suspected, Cisco recommends contacting its Technical Assistance Center and, at minimum, rotating all user credentials, keys, and certificates on the affected Secure FMC device because active exploitation has been ongoing.

No workaround is available. Cisco has released hot fixes for supported Secure FMC releases and recommends upgrading to fixed software. Cloud-delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control are not affected by this vulnerability.

The risk is larger than the CVSS score suggests. Firewall Management Center sits close to policy administration, network segmentation, visibility, and security change control. Access to the management layer can affect the confidence responders have in firewall policies, device state, and the boundaries between internal systems.

Security appliances and management interfaces have become persistent targets because they combine privileged placement with inconsistent monitoring. They are often trusted by default and may sit outside endpoint detection coverage. A low-privileged foothold can become more serious when paired with additional vulnerabilities, excessive administrative reach, weak network access controls, or reused credentials.

Organisations responding to the advisory should patch, restrict management interface exposure, retain and review logs, check for Cisco’s indicators, and rotate credentials and certificates where compromise cannot be ruled out. In regulated and critical environments, security infrastructure also needs to be included in recovery planning as a system that can fail or be compromised, not only as a control protecting other systems.

×