Open Nav
Sign Up

Cisco FMC Zero-Day CVE-2026-20316 Actively Exploited to Access Sensitive Data

cve-2026-20316

Filip Dimitrov

July 30, 2026

Cisco has disclosed an actively exploited vulnerability in Cisco Secure Firewall software that allows unauthenticated remote attackers to gain access to affected systems using static credentials.

Tracked as CVE-2026-20316, the vulnerability has a CVSS score of 5.3, although Cisco has assigned it a High Security Impact Rating because the flaw is being exploited in the wild and can potentially be chained with other Cisco FMC vulnerabilities to escalate privileges.

The US Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-20316 to its Known Exploited Vulnerabilities (KEV) catalogue, confirming that the vulnerability poses an immediate threat to organisations running affected Cisco infrastructure.

What Is CVE-2026-20316?

CVE-2026-20316 is a static credential vulnerability affecting the web interface of Cisco Secure Firewall Management Center Software.

The issue exists because FMC contains static credentials associated with a low-privileged user account.

An unauthenticated attacker who can reach the FMC management interface can use these credentials to authenticate to an affected system without possessing legitimate organisational credentials.

Successful exploitation gives the attacker access to the system with the permissions available to the embedded low-privileged account, including access to potentially sensitive information.

Exploitation can occur remotely, requires low attack complexity, requires no prior privileges and does not require user interaction. 

Why CVE-2026-20316 Presents a Significant Risk

Although CVE-2026-20316 carries a CVSS score of only 5.3, organisations should not treat it as a typical medium-severity vulnerability.

Cisco has explicitly assigned the vulnerability a High Security Impact Rating, noting that access gained through the static account can potentially be combined with other Cisco Secure FMC vulnerabilities to escalate privileges. 

Exploitation Activity

Cisco’s Product Security Incident Response Team (PSIRT) confirmed that it became aware of active exploitation during July 2026. Cisco has not publicly attributed the attacks to a specific threat actor or disclosed the full exploitation chain being used. A subsequently added the vulnerability to its Known Exploited Vulnerabilities catalogue on 29 July 2026. 

Affected Cisco Products

CVE-2026-20316 affects Cisco Secure Firewall Management Center (FMC) Software across supported configurations. The vulnerability is present in the FMC web interface and does not depend on a specific optional feature or device configuration being enabled.

How to Determine Exposure

Administrators should enter expert mode on their FMC appliance and inspect /var/log/messages for references to license:

cat /var/log/messages | grep license

Cisco advises that the presence of the following file path within the resulting log entries could indicate exploitation:

/var/tmp/license.tmp

An example malicious or suspicious entry provided by Cisco involves the www account invoking:

/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp –lsm

The presence of /var/tmp/license.tmp should therefore trigger immediate incident investigation rather than being treated solely as a patch-management issue. co recommends contacting its Technical Assistance Center (TAC) if exploitation is suspected.

Because active exploitation has already occurred, Cisco also recommends rotating all user credentials, cryptographic keys and certificates stored on the affected FMC device where compromise may have taken place. 

Mitigation and Remediation

Cisco has released dedicated hot fixes for affected Secure FMC versions:

Cisco Secure FMC releaseHot fix
7.0Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar
7.2Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar
7.4Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar
7.6Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar
7.7Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar
10.0Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar

Cisco states that no workaround is available, meaning patching is required to fully remediate the vulnerability. anisations using Cisco Secure FMC should:

  1. Identify all affected FMC instances and determine their current software versions.
  2. Apply Cisco’s corresponding hot fix immediately.
  3. Check /var/log/messages for /var/tmp/license.tmp and investigate any matching activity.
  4. Restrict FMC management interfaces from direct internet exposure and limit management access to trusted administrative networks.
  5. Review authentication and administrative activity for unexpected access or anomalous behaviour.
  6. If exploitation is suspected, rotate credentials, keys and certificates associated with the FMC appliance and contact Cisco TAC for recovery assistance.

Stay Safe. Stay Secure

OP Innovate Research Team

Under Cyber Attack?

Fill out the form and we will contact you immediately.