Cisco disclosed an actively exploited zero-day vulnerability in Secure Firewall Management Center (FMC) software — CVE-2026-20316 — caused by hardcoded static credentials (CWE-259) for a low-privileged built-in account, with no workaround available. Although the vulnerability carries only a CVSS score of 5.3, Cisco assigned a "High" security-impact rating because the foothold can be chained with other FMC flaws to escalate privileges on the device governing an entire firewall estate, the Qualys Threat Protection team reported on July 31.
Federal Deadline: August 1
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 29 with an August 1 remediation deadline for federal agencies. Affected versions include FMC 7.0, 7.1, 7.2, 7.3, 7.6, and 7.7 prior to specific patch releases. Cisco has released hotfixes for all affected lines — the only remedy, since no workaround exists.
"Indicators of compromise include log entries referencing /var/tmp/license.tmp; administrators should run 'cat /var/log/messages | grep license' in expert mode to check," Cisco said in its advisory.
Why FMC Is a Prime Target
FMC is the centralized management plane for Cisco's Secure Firewall product line — the control point for the security policies of thousands of organizations. An attacker who compromises FMC can silently alter rules, disable protections, and exfiltrate configuration data across every managed firewall. The disclosure follows a wave of firewall-management-plane attacks this year, and security analysts said organizations that have not yet applied hotfixes should treat the deadline as urgent regardless of whether they are covered by federal requirements.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.