Active Exploitation of Vulnerability in Cisco Secure Firewall Management Center
31 July 2026
ttackers are exploiting a medium-severity vulnerability in Cisco Secure Firewall Management Center to log in and access sensitive data. Patch immediately.
Background
Cisco has released security updates to address a medium-severity vulnerability (CVE-2026-20316) affecting Cisco Secure Firewall Management Center. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 5.3 out of 10.
Impact
The vulnerability is caused by the presence of built-in (static) login details for a low-privileged account. An unauthenticated, remote attacker could use these details to log in to an affected system and access sensitive data as that low-privileged user. If the management interface is not reachable from the public internet, the exposure to this vulnerability is reduced. Cisco notes that this vulnerability can be used together with other Cisco Secure Firewall Management Center vulnerabilities to gain higher privileges.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects Cisco Secure Firewall Management Center versions:
7.0.0 through 7.0.9
7.2.0 through 7.2.11
7.3.0 through 7.3.1.2
7.4.0 through 7.4.7
7.6.0 through 7.6.5
7.7.0 through 7.7.12
10.0.0 through 10.0.1
Users and administrators should refer to the vendor advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
