top of page
perceptive_background_267k.jpg

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Published:

29 juli 2026 om 23:35:40

Alert date:

30 juli 2026 om 00:00:53

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Network Infrastructure, Zero-Day Vulnerabilities, Identity & Access

Cisco has issued a warning about a high-severity vulnerability in its Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, involving a static credential flaw. The vulnerability has been actively exploited in zero-day attacks, allowing threat actors to gain unauthorized access to vulnerable devices. Static credentials embedded in software are a critical risk as they cannot be changed by end users and provide persistent access if discovered. Cisco's FMC is a widely deployed enterprise security management platform, making this vulnerability particularly impactful across organizations relying on Cisco firewall infrastructure. The zero-day nature of the exploitation means attacks were occurring before a patch or public disclosure was available. Organizations using affected FMC versions are urged to apply mitigations or patches immediately.

Technical details

CVE-2026-20316 is a high-severity static credential vulnerability in Cisco Secure Firewall Management Center (FMC) Software. It involves hardcoded credentials for a built-in low-privilege account, allowing an unauthenticated remote attacker to log in and access sensitive data. Despite a CVSS score of 5.3, it is rated High severity because the access can be combined with other unspecified FMC vulnerabilities to elevate privileges. Active exploitation was detected in July 2026. A separate critical vulnerability, CVE-2026-20079 (CVSS 10.0), is an authentication bypass flaw caused by an improper system process created at boot time. It allows an unauthenticated remote attacker to bypass authentication entirely and execute scripts and commands as root via specially crafted HTTP requests, without requiring any credentials. CVE-2026-20079 was originally disclosed in March 2026 and updated July 29 with a second bug ID, hot fixes, and IOCs. Both vulnerabilities share the same /var/tmp/license.tmp indicator of compromise, though Cisco has not clarified whether they are connected. Exploitation evidence includes the FMC web process (www account) invoking package_info.pl as root with the /var/tmp/license.tmp file as an argument.

Mitigation steps:

1. Install available hot fixes released by Cisco for Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 immediately — no workarounds exist. 2. Reduce attack surface by ensuring the FMC management interface is not exposed to the public internet. 3. Check for compromise by reviewing /var/log/messages log file: run 'cat /var/log/messages | grep license' in expert mode and look for entries referencing /var/tmp/license.tmp. 4. If the IOC is found, rotate all user credentials, keys, and certificates on the affected FMC device. 5. Organizations believing they are compromised should contact Cisco TAC for recovery assistance. 6. Note: Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control are not affected.

Affected products:

Cisco Secure Firewall Management Center (FMC) Software - releases 7.0
7.2
7.4
7.6
7.7
and 10.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

/var/tmp/license.tmp, Log entry pattern: sudo www account invoking /usr/local/sf/bin/package_info.pl with /var/tmp/license.tmp --lsm argument, Example log: Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm, Grep command: cat /var/log/messages | grep license

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page