


Perceptive Security
SOC/SIEM Consultancy

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Published:
30 July 2026 at 07:08:39
Alert date:
30 July 2026 at 08:00:52
Source:
thehackernews.com
Network Infrastructure, Zero-Day Vulnerabilities, Identity & Access
CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog after reports of active zero-day exploitation targeting Cisco Secure Firewall Management Center (FMC) Software. The vulnerability carries a CVSS score of 5.3 and allows an unauthenticated, remote attacker to log in using static credentials, potentially exposing sensitive data. The flaw resides in the FMC software and poses a risk to organizations relying on Cisco's firewall management infrastructure. CISA's addition to the KEV catalog signals confirmed in-the-wild exploitation. Organizations using Cisco FMC are urged to apply patches or mitigations immediately. The presence of static credentials as an attack vector highlights a significant authentication design weakness.
Technical details
CVE-2026-20316 (CVSS 5.3) is a vulnerability in Cisco Secure Firewall Management Center (FMC) Software caused by the presence of static user credentials for a low-privileged account. An unauthenticated remote attacker can use these hardcoded credentials to log in and access sensitive data. Although rated Medium by CVSS, Cisco assigned a High Security Impact Rating (SIR) because the flaw can be chained with CVE-2026-20079 (CVSS 10.0), a critical authentication bypass vulnerability that enables execution of arbitrary executable script files to obtain root access. The same IoC (/var/tmp/license.tmp) appears in both vulnerabilities, suggesting threat actors may be chaining them for full code execution. Attack surface is reduced if the FMC management interface is not exposed to the public internet. CVE-2026-20079 has been updated with a second bug ID (CSCwt95974) and the same IoCs and hotfixes. The vulnerability was discovered by Jimi Sebree of Horizon3.ai and was actively exploited earlier in July 2026.
Mitigation steps:
1. Apply the relevant hotfix for your Cisco Secure FMC Software version immediately: v7.0 -> Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar; v7.2 -> Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar; v7.4 -> Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar; v7.6 -> Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar; v7.7 -> Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar; v10.0 -> Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar. 2. FCEB agencies must apply fixes by August 1, 2026. 3. Check for IoCs by running the CLI command in expert mode: cat /var/log/messages | grep license — if output includes '/var/tmp/license.tmp', the device may have been compromised. 4. Restrict the FMC management interface from public internet access to reduce the attack surface. 5. Also apply hotfixes for CVE-2026-20079 given the potential for chaining.
Affected products:
Cisco Secure Firewall Management Center (FMC) Software 7.0
Cisco Secure Firewall Management Center (FMC) Software 7.2
Cisco Secure Firewall Management Center (FMC) Software 7.4
Cisco Secure Firewall Management Center (FMC) Software 7.6
Cisco Secure Firewall Management Center (FMC) Software 7.7
Cisco Secure Firewall Management Center (FMC) Software 10.0
Related links:
https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
https://thehackernews.com/2026/03/cisco-confirms-active-exploitation-of.html
Related CVE's:
Related threat actors:
IOC's:
/var/tmp/license.tmp, CLI command output containing: /var/tmp/license.tmp when running: cat /var/log/messages | grep license, Log entry example: sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm
This article was created with the assistance of AI technology by Perceptive.
