Security

Cisco Discloses Actively Exploited Zero-Day in Secure Firewall Management Center With No Workaround

The flaw — hardcoded static credentials in FMC versions 7.0 through 7.7 — is in CISA's Known Exploited Vulnerabilities catalog with an August 1 federal remediation deadline, and Cisco says patching is the only fix.

N
By Nina Kowalski Security Analyst
August 2, 2026 / 6 min read

Cisco disclosed an actively exploited zero-day vulnerability in Secure Firewall Management Center (FMC) software — CVE-2026-20316 — caused by hardcoded static credentials (CWE-259) for a low-privileged built-in account, with no workaround available. Although the vulnerability carries only a CVSS score of 5.3, Cisco assigned a "High" security-impact rating because the foothold can be chained with other FMC flaws to escalate privileges on the device governing an entire firewall estate, the Qualys Threat Protection team reported on July 31.

Federal Deadline: August 1

CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 29 with an August 1 remediation deadline for federal agencies. Affected versions include FMC 7.0, 7.1, 7.2, 7.3, 7.6, and 7.7 prior to specific patch releases. Cisco has released hotfixes for all affected lines — the only remedy, since no workaround exists.

"Indicators of compromise include log entries referencing /var/tmp/license.tmp; administrators should run 'cat /var/log/messages | grep license' in expert mode to check," Cisco said in its advisory.

Why FMC Is a Prime Target

FMC is the centralized management plane for Cisco's Secure Firewall product line — the control point for the security policies of thousands of organizations. An attacker who compromises FMC can silently alter rules, disable protections, and exfiltrate configuration data across every managed firewall. The disclosure follows a wave of firewall-management-plane attacks this year, and security analysts said organizations that have not yet applied hotfixes should treat the deadline as urgent regardless of whether they are covered by federal requirements.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.