Top Advisory

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Severity Level: Medium

Date: 05/08/2026

Ref: CERT-NCSOC-0247

Components Affected

Overview

Cisco Secure Firewall Management Center (FMC) Software contains a hardcoded, static credential for a low-privileged built-in account. A remote attacker with no authentication can use this account to log in to an affected FMC and access sensitive data.

Description

A vulnerability has been identified in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The issue stems from the presence of static, hardcoded user credentials tied to a low-privileged built-in account within the FMC software. Because these credentials are embedded in the software itself rather than being unique per deployment, any attacker aware of them can use this account to authenticate to the web interface without needing valid credentials of their own. CWE-259: Use of Hard-coded Password. By exploiting this vulnerability, an attacker can successfully log in to the affected system using the low-privileged account and access sensitive data that is available to that account. While the access gained is limited to what the low-privileged account can view, this still exposes information that should otherwise require authentication to reach.

Although the CVSS scoring for this vulnerability would typically correspond to a Medium severity rating, Cisco has assigned it a Security Impact Rating (SIR) of High. This elevated rating reflects the fact that access gained through this low-privileged account can potentially be combined with other, separate vulnerabilities in Cisco Secure FMC Software to escalate privileges further, potentially leading to a more severe compromise of the affected system beyond what this vulnerability alone would allow.

Cisco has confirmed that this vulnerability is being actively exploited in the wild, and it has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for organizations running affected FMC deployments to remediate promptly. CWE-259: Use of Hard-coded Password. CVSS Base Score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Cisco Security Impact Rating (SIR): High

Impact

Solution / Workarounds

Before installation of the software, please visit the vendor website for more details. Cisco strongly recommends upgrading to a fixed release or applying the following fixes:

Reference

Disclaimer

The information provided herein is based on public vendor and government sources available as of 28 July 2026 and is provided on an "as is" basis, without warranty of any kind.

Footer Advisory