Cisco has confirmed active zero-day exploitation of a high-severity vulnerability in Secure Firewall Management Center (FMC) software, tracked as CVE-2026-20316. The flaw stems from a static, hard-coded credential tied to a low-privilege account built into the FMC software, allowing an unauthenticated remote attacker to log in and access sensitive data available to that account.
Cisco rated the issue High severity despite a CVSS base score of 5.3, noting that access gained through the static credential could be chained with other unspecified FMC vulnerabilities to escalate privileges. The company has not disclosed which additional flaws are involved or how attackers are combining them.
The vulnerability affects Cisco Secure FMC Software regardless of device configuration, but does not impact Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, or Security Cloud Control. Hot fixes are available for FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. There are no workarounds, and Cisco is urging immediate patching. Cisco says it became aware of exploitation in July 2026 but has not detailed when attacks began or who is responsible. Jimi Sebree of Horizon3.ai is credited with reporting the flaw.
Indicators of Compromise
Cisco advises administrators to reduce exposure by keeping the FMC management interface off the public internet, and to check /var/log/messages in expert mode for signs of compromise. A log entry referencing /var/tmp/license.tmp, showing the FMC web process invoking package_info.pl as root, may indicate exploitation. Organizations finding this indicator should rotate all credentials, keys, and certificates on the affected device and contact Cisco TAC for recovery assistance.
Related critical authentication bypass flaw
Cisco also updated an advisory for a separate, unrelated-in-name but similarly indicator-linked critical FMC authentication bypass vulnerability, CVE-2026-20079, which carries a maximum CVSS score of 10.0. That flaw, caused by an improper system process created at boot, lets an unauthenticated attacker execute commands as root via crafted HTTP requests, without needing the static credential from CVE-2026-20316. Originally disclosed in March 2026, the advisory was updated July 29 with hot fixes and the same license.tmp indicator, though Cisco has not clarified whether the two vulnerabilities are connected. Cisco says it is not currently aware of exploitation of CVE-2026-20079.
CISA action
CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, requiring Federal Civilian Executive Branch agencies to remediate under Binding Operational Directive 26-04. CISA encourages all organizations to prioritize patching this flaw given confirmed active exploitation.
