Cisco Security Advisory
Follow
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
A vulnerability exists in Cisco Secure Firewall Management Center (FMC) Software's web interface. This issue allows an unauthenticated, remote attacker to access sensitive data. The vulnerability stems from the presence of static user credentials for a low-privileged account. An attacker can exploit this by using these credentials to log into an affected system. A successful intrusion grants the attacker access to sensitive data as that low-privileged user. While internet-facing FMC interfaces increase the risk, the attack surface is smaller otherwise. Cisco rated this vulnerability as High, not Medium, due to its potential for privilege escalation when combined with other vulnerabilities. Software updates have been released by Cisco to fix this issue. There are currently no workarounds available to mitigate this vulnerability. The assigned CVE is CVE-2026-20316.