Published on July 30, 2026

Cisco Warns of FMC Static Credential Flaw Exploited in Zero-Day Attacks


Severity

Critical

Detail

Security researchers and Cisco have disclosed a high-severity vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, which has been actively exploited in zero-day attacks. The vulnerability is caused by the presence of static credentials associated with a low-privilege account built into Cisco Secure FMC Software.

An unauthenticated remote attacker could exploit this vulnerability by using the embedded credentials to access an affected FMC system and retrieve sensitive information available to the compromised account. Although the vulnerability has a CVSS score of 5.3, Cisco has rated it as High severity due to the potential for attackers to combine this access with additional vulnerabilities to achieve privilege escalation and further compromise the affected system.

The vulnerability affects Cisco Secure FMC Software regardless of device configuration. However, it does not impact Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, or Security Cloud Control.

Cisco confirmed that active exploitation began in July 2026, but has not disclosed details regarding the threat actors, targeted organizations, or the full attack timeline. Organizations are advised to apply the available security hot fixes immediately, as no workaround is available to fully mitigate the vulnerability.

In addition, Cisco has updated its advisory for a separate critical vulnerability, CVE-2026-20079, which allows unauthenticated remote attackers to bypass authentication and execute commands as root through specially crafted HTTP requests. While Cisco has not confirmed active exploitation of CVE-2026-20079, the same indicators of compromise were published for both vulnerabilities.

CVE IDSummaryCVSS Score
CVE-2026-20316A static credential vulnerability in Cisco Secure FMC Software allows unauthenticated remote attackers to access the system using built-in credentials and potentially perform further attacks through privilege escalation.5.3 (Medium) / Cisco Severity: High
CVE-2026-20079An authentication bypass vulnerability in Cisco Secure FMC Software allows unauthenticated remote attackers to execute scripts and commands as root through crafted HTTP requests.10.0 (Critical)

Affected Products

The vulnerabilities affect the following:

  • Cisco Secure Firewall Management Center (FMC) Software
  • Cisco Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0

The vulnerabilities do not affect:

  • Cloud-Delivered FMC
  • Firewall Device Manager
  • Secure Firewall ASA Software
  • Secure Firewall Threat Defense Software
  • Security Cloud Control


Recommendation

Organizations should implement the following measures to reduce the risk of exploitation:

  • Apply Cisco-provided hot fixes for CVE-2026-20316 and CVE-2026-20079 immediately.
  • Avoid exposing Cisco FMC management interfaces directly to the public internet where possible.
  • Review /var/log/messages for suspicious activity related to /var/tmp/license.tmp.
  • Investigate any FMC devices showing indicators of compromise and perform incident response activities.
  • Rotate all user credentials, cryptographic keys, and certificates on affected FMC devices if exploitation is suspected.
  • Maintain regular monitoring of administrative access and unusual commands executed on network management appliances.

Source

https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks

https://nvd.nist.gov/vuln/detail/CVE-2025-20316

https://nvd.nist.gov/vuln/detail/CVE-2026-20079