Cisco has warned that attackers are exploiting a high-severity vulnerability in Secure Firewall Management Center software. The Cisco FMC static credential flaw can give remote attackers unauthorised access to vulnerable devices.
Tracked as CVE-2026-20316, the issue involves built-in credentials for a low-privilege account. Cisco has released hot fixes for affected versions and says customers should apply them without delay.
Built-in account creates an access risk
The vulnerability stems from static credentials embedded in Cisco Secure FMC Software. An unauthenticated remote attacker can use those credentials to sign in to an affected device.
After gaining access, the attacker can view sensitive data available to the built-in account. The flaw has a CVSS score of 5.3, yet Cisco has rated it High severity.
That higher rating reflects the risk of chaining the vulnerability with other flaws to obtain elevated privileges. Cisco has not identified the additional vulnerabilities involved or explained how attackers use them in active attacks.
Cisco confirms active exploitation
The company became aware of active exploitation in July 2026. It did not reveal when the attacks began, who may be responsible or which organisations may have been targeted.
Jimi Sebree of Horizon3.ai reported the vulnerability.
CVE-2026-20316 affects Cisco Secure FMC Software regardless of device configuration. However, Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software and Security Cloud Control are not affected.
Hot fixes are available for Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. No workaround fully addresses the issue, making patching the only reliable solution.
Check systems for signs of compromise
Keeping the FMC management interface off the public internet can reduce the attack surface. Even so, administrators should check affected devices for evidence of earlier exploitation.
Cisco advises reviewing the /var/log/messages file for suspicious activity linked to /var/tmp/license.tmp. A log entry showing the FMC web process, running as the www account, calling the package_info.pl script as root with that temporary file may indicate compromise.
If this indicator appears, administrators should rotate every user credential, key and certificate on the affected FMC device. Organisations that suspect a breach should also contact Cisco TAC for recovery assistance.
Critical authentication bypass flaw also patched
Cisco has also updated its advisory for CVE-2026-20079, a separate critical vulnerability in Secure FMC. This flaw carries a maximum CVSS score of 10.0.
An unauthenticated remote attacker could bypass authentication and execute scripts or commands as root by sending specially crafted HTTP requests. The weakness results from an improper system process created during device boot.
Unlike CVE-2026-20316, this flaw does not depend on static credentials or prior access to the device. Cisco first disclosed it in March 2026 and updated its advisory on July 29 with a second bug ID, hot fixes and compromise indicators.
The company said it has no evidence that attackers have exploited CVE-2026-20079 in the wild.
Shared indicator raises questions
Both advisories list /var/tmp/license.tmp as a possible compromise indicator. However, Cisco has not explained whether the two vulnerabilities are connected.
The shared indicator is notable because the authentication bypass flaw could potentially provide root access without using the static credentials tied to CVE-2026-20316.
Organisations should install the available hot fixes, restrict exposure of FMC management interfaces and investigate suspicious log entries immediately.


0 responses to “Cisco FMC Static Credential Flaw Exploited in Zero-Day Attacks”