Cisco’s Secure Firewall Management Center (FMC) has been left vulnerable to unauthorized access due to a high-severity static credential flaw, which has already been exploited in zero-day attacks. The vulnerability, tracked as CVE-2026-20316, allows an unauthenticated attacker to log in to an affected system and access sensitive data available to the account.
The issue lies in the fact that Cisco Secure FMC Software contains static credentials for a low-privilege account, which can be used by attackers to gain access. This vulnerability is particularly concerning because it does not require any prior access or knowledge of the device’s configuration. According to Cisco, an attacker can use these credentials to log in and access sensitive data, although the company has assigned a High severity rating due to the potential for elevated privileges through combination with other vulnerabilities.
It’s worth noting that this vulnerability affects Cisco Secure FMC Software regardless of device configuration, but does not impact other products such as Cloud-Delivered FMC or Firewall Device Manager. To address the issue, Cisco has released hot fixes for affected software releases, and customers are strongly advised to install these patches as soon as possible.
Cisco became aware of active exploitation in July 2026 but has not shared further details on when the attacks began, who is behind them, or which organizations were targeted. Jimi Sebree from Horizon3.ai reported the vulnerability to Cisco. The company also notes that reducing the attack surface by keeping the FMC management interface inaccessible to the public internet can help mitigate the risk.
Administrators are advised to review log files for signs of exploitation and search for suspicious activity using commands such as `cat /var/log/messages | grep license`. A specific indicator of compromise (IOC) is a log entry containing `/var/tmp/license.tmp`, which may indicate that an FMC device was compromised. If detected, administrators should rotate all user credentials, keys, and certificates on the affected FMC device.
In related news, Cisco also updated its advisory for a separate critical FMC authentication bypass vulnerability, tracked as CVE-2026-20079, which has a maximum CVSS score of 10.0. This flaw allows an attacker to bypass authentication and execute scripts and commands as root without requiring credentials or prior access to the device. While Cisco is not aware of malicious exploitation, it’s essential for organizations to stay vigilant and take prompt action to address these vulnerabilities.
In light of this incident, security teams should test their defenses regularly to ensure they can detect and respond effectively to attacks. By doing so, organizations can reduce the likelihood of successful breaches and minimize the impact when an attack does occur.
Source: Bleeping Computer — 2026-07-29