decrypted · 3 august 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain
A hardcoded password in Cisco's firewall console, and the NHS alert that followed
Cisco disclosed on 29 July that its Secure Firewall Management Center, the console thousands of organisations use to administer fleets of firewalls, ships with a password built into the software itself. CISA added the flaw to its exploited-vulnerabilities list the same day, giving US federal agencies until 1 August to patch. NHS England Digital sent its own alert to health bodies running the product on 30 July. None of that urgency shows up in the bug's official severity score, which is the most useful part of this story.
A spare key moulded into every lock
CVE-2026-20316 sits in a low-privileged account inside Secure Firewall Management Center (FMC), the tool administrators use to push policy to their Cisco firewalls. The credentials for that account are static: identical on every install, not something a customer set, and not something a customer can rotate through the normal admin interface. Anyone who can reach the FMC web console can log in as that account and pull sensitive configuration data straight out of it. Cisco also warned it can be chained with other FMC flaws to climb further in.
It is the security equivalent of a lock manufacturer casting a spare key into every unit it sells. You can change your own key as often as you like; the factory-moulded one still opens the door, on your house and everyone else's who bought that model. Cisco has released hotfixes for the affected releases, 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, and says there is no workaround short of installing them.
Why the number undersold it
Cisco scored this 5.3 out of 10, medium by the numbers, then separately rated it a high Security Impact Rating because of what it enables when combined with other bugs. That gap is the lesson for anyone triaging by CVSS alone: a static credential is not a normal bug you weigh by exploitability and impact, it is a design decision that removes a control an organisation thinks it has. It is exactly the category of flaw that "secure by design" work, including CISA's pledge and NCSC's own guidance, targets by name: eliminate hardcoded and default passwords rather than patch around them release after release.
For UK organisations running FMC, the immediate list is short: apply the hotfix, follow Cisco's advice to keep the management interface off the open internet, and check logs for the indicators Cisco has published. The wider point is procurement, not just patching: when you buy management software for security infrastructure, ask the vendor directly whether any account, anywhere in the product, has a credential you cannot change. If the answer is yes, that is a finding, not a footnote.
Also this week
EY. The extortion group ShinyHunters says it stole tax-related client files after compromising a third-party IT service management platform used by EY staff, and set a 31 July deadline before publishing. EY disclosed the underlying incident in July, says it detected the activity in April, and has offered affected clients credit monitoring. It has not confirmed ShinyHunters' account of how far the access spread. The lesson travels well beyond one firm: any organisation routing sensitive client data through a third-party support platform is trusting that platform's security as much as its own.
Analog Devices. The chipmaker, whose parts sit in industrial and automotive supply chains that reach UK manufacturers, disclosed a breach after detecting unauthorised access on 23 June. The extortion group ExfilSquad has claimed responsibility and listed the company on its leak site, though Analog Devices says it has no evidence stolen data has been leaked or misused, and the group has since delisted the entry, a pattern that often means negotiations are under way. Worth watching, but still a claim rather than a confirmed loss.
NCSC. In a blog post on 29 July, NCSC technical director Chris A called on manufacturers of firewalls, VPN gateways and similar network devices to build in "forensic observability" from the outset, so defenders can establish what a compromised device did without, in his words, "discovering or exploiting vulnerabilities in the product itself." It is a direct response to a recurring pattern this year: devices that sit at the network edge get attacked first, and offer investigators the least evidence when they do.
Sources
- Cisco Security Advisory: Cisco Secure Firewall Management Center Software Static Credential Vulnerability
- NHS England Digital: Cisco Releases Security Advisory for Vulnerability in Secure Firewall Management Center (cc-4822)
- BleepingComputer: Cisco warns of FMC static credential flaw exploited in zero-day attacks
- NCSC: Making forensic observability the norm for network devices
- BleepingComputer: Analog Devices discloses data breach, says operations unaffected
- Hackread: ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak
If any of this raises questions about your own exposure, get in touch.
More like this
- The npm maintainer account North Korea phished, and the four packages it unlocked 31 july 2026
- Anthropic's Claude broke into three real companies during a safety test 2 august 2026
- The Department for Education's helpdesk, and the 607,000 records it was never built to hold 31 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.