[CIVN-2026-0385] Information Disclosure Vulnerability in Cisco Product

By Published On: August 4, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Information Disclosure Vulnerability in Cisco Product


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: MEDIUM


Software Affected


Cisco Secure Firewall Management Center (FMC) Software

Overview


A vulnerability has been reported in Cisco Secure FMC Software which could allow an unauthenticated remote attacker to log in to the affected system using the static credentials and access sensitive information.


Target Audience:

All IT administrators and individuals responsible for maintaining and updating in Software.


Risk Assessment:

High risk of unauthorized access to sensitive information.


Impact Assessment:

Information disclosure and unauthorized access.


Description


The vulnerability exists in Cisco Secure FMC Software due to the presence of hard-coded (static) credentials for a low-privileged user account in the web interface. An unauthenticated, remote attacker could exploit this vulnerability by authenticating with the static credentials.


Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to log in to the affected system using the static credentials and access sensitive information.


Solution


Apply appropriate updates as mentioned in Cisco Advisory

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh


CVE Name

CVE-2026-20316




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpx8NwACgkQ3jCgcSdc

ys8ZfA/9Hc4/LceJYBSIkfVz5hiqsmWiRP70yQ4dqocLxHMgjitCS1yqMuWF+X9c

KoJKyQdtfle9SfsubV+chZDiDuImkhO9fJZzSCAtZnoJvHl3QIwedz/K43hvILBH

4KKlEtB35ziatebOl8IjVZ0rItfj3gw7wcQjFPDkKiHZMlo6P3ZfoyFKArAhMie0

/qY2etVNbt5beHL2MbpjJBhkM57mm+I1bs3HgEZSp2v2+fUV0CG7qD1/dK64z8PN

5fSoTlW4Xiu1MCkKC9Hui1aCS047kaPlcFOUo0HfPYGV8HBdOX1CbmTHYqGhiKe8

q7DblwhE8aobV9mDaWuYEruEhvYXR8CgDOu4jIbM7g1H2seXr9Dlznn415VDppq5

XE53YgOLMTkdfxe3XZm/7W7IjN0wjvtTRZzFJg052nyBPDnpxnk839CjfeB00vJS

8h/PVujLFcZIzwItULITlX50d/gd3EB9oQrBVL46/kTNaxCCPzdrj/yL6S6rrkUx

2Sc2a/5mb6IMNb2BnNpsfD5Wmqudv5NQ2a4ao1IpKIFDucv0DprwMk2UtA/yjjKv

0xC8eEbOMMv9/phj8TimKUHfftafJdMTUegC2pHisJgMhA6i6SvkL6EJAzZRKFYs

6UL6yGHT93aiSh0emoI1PStmVLxv4T7fF12LaddUzH+moMXJCFM=

=1c3z

—–END PGP SIGNATURE—–

Share this article