CISA warns hackers are abusing a built-in Cisco firewall password

The US Cybersecurity and Infrastructure Security Agency says attackers are actively exploiting a hard-coded password in Cisco Secure Firewall Management Center, the console many enterprises use to run their entire firewall estate.

CISA added the flaw, tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) catalog on July 29, 2026, citing evidence of exploitation in the wild. A hard-coded password is a credential written into the software itself rather than chosen by the customer, so it cannot simply be changed, and anyone who learns it can log in as though they belong there.

Why the management console matters

Secure Firewall Management Center is the control plane for Cisco Secure Firewall (formerly Firepower) deployments. It distributes policy and rule updates to the firewalls and collects their logs. Scope matters here, and it cuts against the instinct to treat every KEV entry as a five alarm fire. Cisco scores the flaw CVSS 3.1 base 5.3, Medium, with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. That describes limited confidentiality impact and nothing else: no integrity, no availability. The static credential logs an unauthenticated remote attacker in as a built-in low privileged account and lets them read sensitive data on the system. On its own it does not let them rewrite firewall policy, push rules to managed devices, or take the console over. Cisco nevertheless rates the advisory High rather than Medium, and says exactly why: the account can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges. That is the real risk model. The danger is not this bug landing, it is this bug landing as step one, because a foothold on the control plane for a fleet of firewalls is worth far more to an intruder than 5.3 suggests. Treat it as an access primitive, not as game over. CISA describes this class of bug as a frequent attack vector that poses significant risk to federal networks.

What CISA has not said

The KEV entry is deliberately terse. It does not name the attackers, explain how the credential is being reached, say how many organizations have been affected, or indicate whether the activity is criminal or state-linked. CISA's published bar for adding an entry is a CVE ID, evidence of exploitation, and clear mitigation guidance, not a full incident narrative. Treat broader claims about this campaign with caution until Cisco or CISA publishes more.

What you should do

For federal agencies that last step is now an obligation rather than advice. Binding Operational Directive 26-04 tells civilian agencies to prioritize rapid remediation of KEV-listed flaws on publicly exposed assets that hand an attacker total control after exploitation, defer lower-risk work, and check whether they were compromised before the patch was applied. The directive binds only federal civilian agencies, but CISA encourages every organization to manage vulnerabilities the same risk-based way. This bug fits the profile it was written for: internet exposed, already exploited, and a credible first step toward full control when chained with a second FMC flaw.

The addition follows a separate KEV batch earlier the same week covering actively exploited flaws in Fortinet and Arista network products, and an earlier round that included Cisco Unified Communications Manager. The entry is documented in CISA's original alert.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions