TL;DR
Cisco is warning about a Cisco FMC vulnerability under active attack. Tracked as CVE-2026-20316, it lets a remote attacker log in using a hidden static account. Cisco confirms exploitation, and CISA has added the bug to its Known Exploited Vulnerabilities catalog.
- CVE: CVE-2026-20316
- CVSS: 5.3 (Medium · CVSSv3)
- Product: Cisco Secure Firewall Management Center (FMC)
- Affected: 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0 (+61 more)
- Impact: Cisco Secure Firewall Management Center Software Static Credential Vulnerability
- Status: Exploited in the wild
- Action: See vendor advisory
Why it matters
FMC is the management brain for Cisco Secure Firewall deployments. Access to it can expose sensitive configuration and monitoring data. Cisco rated the issue a High Security Impact, since attackers can chain it to escalate privileges.
How the attack works
The flaw sits in the FMC web interface. It stems from static credentials baked into a low-privileged account. So an unauthenticated attacker can use that built-in account to log in remotely.
A successful login exposes sensitive data as that low-privileged user. On its own, the account is limited. Combined with other FMC bugs, though, it can help an attacker gain more control.
Exploitation status
This is not theoretical. Cisco states that “in July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” CISA then added it to the KEV catalog based on that evidence. Internet-exposed management interfaces face the highest risk.
Affected versions
The Cisco FMC vulnerability affects Secure FMC Software regardless of device configuration. Cisco confirms cloud-delivered FMC, FDM, ASA, and FTD software are not affected. Hot fixes cover releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.
Patch and mitigation
Patch now. Cisco warns that “there are no workarounds that address this vulnerability.” Apply the hot fix for your release from the Cisco advisory. Admins can also check system logs for a license.tmp entry that may signal exploitation.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.