DIRAS TAKE
Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory remediation date, highlighting immediate risk to internet-accessible FMC instances; prioritize mitigations per vendor guidance and CISA instructions.
What is CVE-2026-20316?
An unauthenticated, remote attacker can log in to Cisco Secure Firewall Management Center (FMC) using a static low-privileged account, allowing access to sensitive data. CVE-2026-20316 affects multiple 7.x FMC releases, including 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, and 7.2.0/7.2.0.1. Exploitation requires network access to the FMC management interface; if the interface is not internet-exposed the external attack surface is reduced.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Which versions of Cisco Secure Firewall Management Center (FMC) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.0.0 | |
| 7.x | 7.0.0.1 | |
| 7.x | 7.0.1 | |
| 7.x | 7.0.1.1 | |
| 7.x | 7.0.2 | |
| 7.x | 7.2.0 | |
| 7.x | 7.0.2.1 | |
| 7.x | 7.0.3 | |
| 7.x | 7.2.0.1 | |
| 7.x | 7.0.4 |
Is CVE-2026-20316 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-29, and US federal agencies were required to act by 2026-08-01.
How to fix CVE-2026-20316
- Follow Cisco’s mitigations and guidance for Secure Firewall Management Center immediately.
- Remove or block external network access to the FMC management interface where possible.
- Monitor and audit management interface logins for use of the low-privileged account and other suspicious activity.
- If vendor mitigations are unavailable or exposure cannot be removed, discontinue use or isolate the affected FMC until a fix is provided.
Frequently asked questions
Is CVE-2026-20316 being actively exploited?
CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog on 2026-07-29 and noted known ransomware campaign use, with a remediation due date of 2026-08-01 for US federal agencies.
Which Cisco Secure Firewall Management Center versions are affected by CVE-2026-20316?
Multiple 7.x releases of Cisco Secure Firewall Management Center are listed as affected, including 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, 7.2.0, and 7.2.0.1.
Is there a patch for CVE-2026-20316?
No patch is listed in the available facts; Cisco mitigations and guidance should be applied and exposure restricted until a vendor fix is released.
Does CVE-2026-20316 require authentication?
No — the vulnerability stems from static credentials that allow an unauthenticated, remote actor to log in as a low-privileged account if they can reach the FMC management interface.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20316
- cve.org/CVERecord?id=CVE-2026-20316
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026