CISA warns hackers are abusing a built-in Cisco firewall password

The US Cybersecurity and Infrastructure Security Agency says attackers are actively exploiting a hard-coded password in Cisco Secure Firewall Management Center, the console many enterprises use to run their entire firewall estate.

CISA added the flaw, tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) catalog on July 29, 2026, citing evidence of exploitation in the wild. A hard-coded password is a credential written into the software itself rather than chosen by the customer, so it cannot simply be changed, and anyone who learns it can log in as though they belong there.

Why the management console matters

Secure Firewall Management Center is the control plane for Cisco Secure Firewall (formerly Firepower) deployments. It distributes policy and rule updates to the firewalls and collects their logs. An intruder who reaches that console does not need to defeat the firewalls one by one, because from there they can change what the firewalls permit and read what the firewalls recorded. CISA describes this class of bug as a frequent attack vector that poses significant risk to federal networks.

What CISA has not said

The KEV entry is deliberately terse. It does not name the attackers, explain how the credential is being reached, say how many organizations have been affected, or indicate whether the activity is criminal or state-linked. CISA's published bar for adding an entry is a CVE ID, evidence of exploitation, and clear mitigation guidance, not a full incident narrative. Treat broader claims about this campaign with caution until Cisco or CISA publishes more.

What you should do

For federal agencies that last step is now an obligation rather than advice. Binding Operational Directive 26-04 tells civilian agencies to prioritize rapid remediation of KEV-listed flaws on publicly exposed assets that hand an attacker total control after exploitation, defer lower-risk work, and check whether they were compromised before the patch was applied. The directive binds only federal civilian agencies, but CISA encourages every organization to manage vulnerabilities the same risk-based way. This bug fits the profile it was written for: exposed, already exploited, and total control if it lands.

The addition follows a separate KEV batch earlier the same week covering actively exploited flaws in Fortinet and Arista network products, and an earlier round that included Cisco Unified Communications Manager. The entry is documented in CISA's original alert.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions