• CISA KEV
  • EXPLOITED

CVE-2026-20316: pre-auth authentication bypass in Cisco Secure Firewall Management Center (FMC)

An unauthenticated, remote attacker can log in to Cisco Secure Firewall Management Center (FMC) using a static low-privileged account, allowing access to sensitive data. CVE-2026-20316 affects multiple 7.x FMC releases, including 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, and 7.2.0/7.2.0.1. Exploitation requires network access to the FMC management interface; if the interface is not internet-exposed the external attack surface is reduced.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
5.3MEDIUM
EPSS
0.35096
CWE
CWE-259
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory remediation date, highlighting immediate risk to internet-accessible FMC instances; prioritize mitigations per vendor guidance and CISA instructions.

What is CVE-2026-20316?

An unauthenticated, remote attacker can log in to Cisco Secure Firewall Management Center (FMC) using a static low-privileged account, allowing access to sensitive data. CVE-2026-20316 affects multiple 7.x FMC releases, including 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, and 7.2.0/7.2.0.1. Exploitation requires network access to the FMC management interface; if the interface is not internet-exposed the external attack surface is reduced.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Which versions of Cisco Secure Firewall Management Center (FMC) are affected?

BRANCHAFFECTEDFIXED
7.x7.0.0
7.x7.0.0.1
7.x7.0.1
7.x7.0.1.1
7.x7.0.2
7.x7.2.0
7.x7.0.2.1
7.x7.0.3
7.x7.2.0.1
7.x7.0.4

Is CVE-2026-20316 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-29, and US federal agencies were required to act by 2026-08-01.

How to fix CVE-2026-20316

  1. Follow Cisco’s mitigations and guidance for Secure Firewall Management Center immediately.
  2. Remove or block external network access to the FMC management interface where possible.
  3. Monitor and audit management interface logins for use of the low-privileged account and other suspicious activity.
  4. If vendor mitigations are unavailable or exposure cannot be removed, discontinue use or isolate the affected FMC until a fix is provided.

Frequently asked questions

Is CVE-2026-20316 being actively exploited?

CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog on 2026-07-29 and noted known ransomware campaign use, with a remediation due date of 2026-08-01 for US federal agencies.

Which Cisco Secure Firewall Management Center versions are affected by CVE-2026-20316?

Multiple 7.x releases of Cisco Secure Firewall Management Center are listed as affected, including 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, 7.0.4, 7.2.0, and 7.2.0.1.

Is there a patch for CVE-2026-20316?

No patch is listed in the available facts; Cisco mitigations and guidance should be applied and exposure restricted until a vendor fix is released.

Does CVE-2026-20316 require authentication?

No — the vulnerability stems from static credentials that allow an unauthenticated, remote actor to log in as a low-privileged account if they can reach the FMC management interface.

References