Cisco is warning of a vulnerability in Secure Firewall Management Center that is already being exploited as a zero-day. The cause is a built-in account with static credentials.
The high-severity vulnerability CVE-2026-20316 affects Cisco Secure Firewall Management Center software, known as FMC, through which administrators centrally manage rule sets, updates, and logs for multiple firewalls. The cause is a low-privilege account built into the software that comes with hardcoded credentials. According to Cisco, an unauthenticated, remote attacker can use these credentials to log in to an affected system and access the data available to that account. Although the vulnerability’s CVSS score is 5.3, Cisco has rated it as high risk because the access can be combined with additional, as yet unnamed FMC vulnerabilities to escalate privileges.
Cisco stated that it became aware of active exploitation of the flaw in July 2026, but did not disclose when the attacks began or who is behind them. The US agency CISA added CVE-2026-20316 to its catalog of known, actively exploited vulnerabilities on July 29. The Secure FMC software is affected regardless of the specific device configuration, but the cloud-delivered version of FMC, Firewall Device Manager, Secure Firewall ASA, Threat Defense Software, and Security Cloud Control are not. Cisco has released hot fixes for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0; no workarounds are available.
Additional critical authentication flaw updated
Cisco also updated the advisory for a separate, critical authentication bypass in FMC tracked as CVE-2026-20079, which has a maximum CVSS score of 10.0. Through this flaw, an unauthenticated, remote attacker can bypass authentication and execute scripts and commands with root privileges by sending specially crafted HTTP requests, without needing any credentials or prior access to the device. Cisco had originally disclosed this vulnerability in March 2026 and updated the advisory on July 29 to add a second bug ID, available hot fixes, and indicators of compromise. According to Cisco, no malicious exploitation of this second flaw is currently known.
Recommended checks for administrators
Cisco recommends that administrators review the /var/log/messages log file for signs of a possible compromise. An entry referencing the file /var/tmp/license.tmp may, according to Cisco, indicate that exploitation has occurred. If this indicator is found, administrators should rotate all credentials, keys, and certificates on the affected FMC device and contact Cisco support if a compromise is suspected.
(red)