VORANT. Threat Intelligence Sign in Get the full feed

Cisco Firewall Management Center hardcoded password exploited

high vulnerability government-nationaltechnologyinfrastructure

A hardcoded low-privilege password in Cisco Secure Firewall Management Center's web UI is being actively exploited, per Cisco and CISA KEV.

NCSC-NL published an advisory (NCSC-2026-0271) regarding CVE-2026-20316, a use-of-hard-coded-password vulnerability in the web interface of Cisco Secure Firewall Management Center. The flaw allows unauthenticated remote attackers to log in using a static, low-privileged account credential embedded in the product, granting access without any legitimate login. This access can expose sensitive data managed by the system and, when chained with other vulnerabilities, could enable privilege escalation.

CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating exploitation was observed against US federal government systems. In a 11-09-2026 update, Cisco confirmed successful in-the-wild exploitation of CVE-2026-20316. NCSC-NL urges organizations to apply Cisco's patches immediately and check vulnerable systems for indicators of compromise, referencing Cisco Talos' blog for further guidance.

Defenders running Cisco Secure Firewall Management Center should patch immediately, audit management interface exposure, and ensure web management UIs are not internet-facing but restricted to a separate, isolated management network. Given the CVSS score of 5.3 is relatively low, the real-world risk stems from confirmed active exploitation and unauthenticated access rather than technical severity alone.

Mentioned in this report

Vulnerabilities CVE-2026-20316KEV

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0271.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free