PULSE
FEED
ransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Foundransombraincipher reclama a mulholland.com · US · Not Foundransombraincipher reclama a wildmanbg.com · BG · Otherransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Foundransombraincipher reclama a mulholland.com · US · Not Foundransombraincipher reclama a wildmanbg.com · BG · Other
← Todos los CVEs
CVE Watch16 sept 2026

CVE-2026-20316

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

CVSS

5.3

Medio

EPSS

35.1%

p98

KEV

SÍ

29 jul 2026

Exploit Today

80

0-100

Publicado: 29 jul 2026 · Última mod.: 16 sept 2026 · CWE-259

EPSS · 30d
9.8%EPSS · 30 días35.1%
2026-09-012026-09-28
Ficha del catálogo KEV

Producto

Cisco / Secure Firewall Management Center (FMC)

Vulnerabilidad

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Añadido a KEV

29 jul 2026

Remediar antes de

1 ago 2026

Uso conocido en ransomware

Sí

Descripción resumida

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Acción requerida

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Notas

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316

Descripción técnica

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-704135.6 MED
—
——0Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.1d
CVE-2026-1010527.3 ALT
—
——0A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.1d
CVE-2026-978777.3 ALT
36.8%
——11A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.1d
CVE-2026-965485.6 MED
16.1%
——5A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.6d
CVE-2026-651175.0 MED
12.5%
——4NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.6h
CVE-2026-939707.3 ALT
40.4%
——12A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.6d