Threat Brief — 2026-07-30 — Cisco FMC hard-coded password exploited in the wild
Executive summary. CISA has added CVE-2026-20316KEV—a hard-coded password vulnerability in Cisco Secure Firewall Management Center (FMC)—to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw could allow unauthenticated attackers to gain administrative access to FMC appliances, which serve as the central management plane for Cisco's next-gen firewall estate. No other fresh findings were ingested in the last four hours; the rest of today's threat landscape remains unchanged from prior coverage.
Top items
- [High] CVE-2026-20316KEV — Cisco Secure Firewall Management Center hard-coded password vulnerability, now confirmed exploited in the wild. Cisco FMC (formerly Firepower Management Center) ships with a hard-coded password that attackers can leverage to gain access to the management interface, potentially compromising firewall policies, rules, and configurations across an entire deployment. FMC appliances are the central management layer for Cisco Firepower/FTD firewalls, so compromise here can cascade to all managed firewalls. This vulnerability is now listed in CISA's KEV catalog, meaning federal agencies and private organisations alike should treat patching as urgent. (src: CISA KEV)
Themes
Management-plane credentials remain a persistent weak point. A hard-coded password in a firewall management appliance is the same class of flaw that has plagued IoT devices, VPN concentrators, and network gear for years—but when the target is the centralised management console for an entire firewall fleet, the blast radius is dramatically larger. This joins a recent pattern of attackers targeting management interfaces (Palo Alto GlobalProtect, Fortinet FortiSandbox, SonicWall SMA) rather than individual endpoints.
