Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco has issued a high-severity warning about a static credential flaw in its Secure Firewall Management Center (FMC) software that’s being actively exploited by attackers. The vulnerability, tracked as CVE-2026-20316, allows an unauthenticated attacker to log in to an affected system and access sensitive data using low-privilege credentials built into the FMC software.

The issue is particularly concerning because it can be used in combination with other vulnerabilities to elevate privileges, making it a significant threat to organizations that rely on Cisco’s Secure FMC software. According to Cisco, this vulnerability affects all Secure FMC Software releases, regardless of device configuration, but does not impact Cloud-Delivered FMC, Firewall Device Manager, or other related products.

Cisco has released hot fixes for affected software releases, including 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. However, the company advises that there are no workarounds to address the vulnerability, making it essential for customers to install the available fixes as soon as possible.

What’s particularly disturbing is that Cisco became aware of active exploitation in July 2026, but has not shared information about when the attacks began or which organizations were targeted. The company credits Jimi Sebree from Horizon3.ai with reporting the vulnerability, and notes that the attack surface can be reduced by limiting access to the FMC management interface.

To detect potential compromise, administrators should review the /var/log/messages log file for signs of suspicious activity. Specifically, they should search for any references to the /var/tmp/license.tmp file, as this may indicate exploitation of the vulnerability. If a device contains this indicator of compromise (IOC), it’s essential to rotate all user credentials, keys, and certificates on the affected FMC device.

While Cisco is not aware of malicious exploitation of another critical flaw tracked as CVE-2026-20079, which allows an unauthenticated attacker to bypass authentication and execute scripts as root, the company has released hot fixes for this vulnerability as well. This advisory was originally published in March 2026, but has been updated with new information about the shared IOC.

For organizations that rely on Cisco’s Secure FMC software, it’s essential to take immediate action to mitigate this risk. By installing available hot fixes and regularly monitoring log files for suspicious activity, administrators can significantly reduce the attack surface and prevent potential exploitation of these vulnerabilities.


Source: Bleeping Computer — 2026-07-29