Cisco Secure FMC CVE-2026-20316 Exploited

Cisco Secure FMC CVE-2026-20316 is under active attack via hardcoded credentials that chain into a CVSS 10.0 root bypass. Patch now.

Cisco Secure FMC CVE-2026-20316 is under confirmed active exploitation: a hardcoded, low-privilege account built into every on-premises Secure Firewall Management Center gives an unauthenticated attacker a foothold — and in the same advisory cycle, Cisco quietly reactivated a five-month-old, maximum-severity root-level bypass in the same product, sharing an identical indicator of compromise. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 29, 2026 with a federal deadline of August 1 — a deadline that will already have passed by the time most organizations read this.

What Happened

Cisco Secure FMC CVE-2026-20316 is caused by static, hardcoded credentials for a low-privilege account built into on-premises Cisco Secure FMC Software, regardless of configuration. An unauthenticated remote attacker can use these built-in credentials to log in directly and access sensitive data available to that account. Cisco scores the flaw CVSS 5.3 but assigns it a High Security Impact Rating rather than Medium, explicitly because the access can be chained with other FMC vulnerabilities to escalate privileges — Cisco has not disclosed which additional flaws or how.

In the same July 29 update, Cisco revised a separate, critical advisory for CVE-2026-20079 (CVSS 10.0, originally disclosed in March 2026): an unauthenticated attacker can bypass authentication entirely and execute scripts and commands as root via crafted HTTP requests, no credentials or user interaction required, caused by an improper system process left over from device boot. The updated advisory added a second bug ID, new hotfixes, and the exact same indicator of compromise used for CVE-2026-20316 — a detail Cisco has not explained, but one that strongly suggests the two flaws may be getting chained together in the wild. The issue affects on-premises Secure FMC only; Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense, and Security Cloud Control are unaffected.

Why It Matters

Cisco Secure Firewall Management Center is the single console that administers an organization’s entire firewall fleet. A root-level compromise of that console does not put one appliance at risk — it puts every managed firewall’s policy, logging and configuration under attacker control at once. This is the same “one console, whole fleet” failure pattern DIESEC flagged in Check Point SmartConsole (CVE-2026-16232) just four days earlier, and it is the thirteenth distinct edge-device or network-infrastructure product line exploited in 2026 across DIESEC’s tracking — a pattern that has now spread from firewalls and SD-WAN controllers into the management planes that sit above them.

What You Should Do Now

  1. Install the hotfix for your release branch: 7.0.9.1, 7.2.11.1, 7.4.7.1, 7.6.5.1, 7.7.12.1 or 10.0.1.1. There is no workaround for either CVE.
  2. Verify exposure: confirm whether your FMC management interface is reachable from the public internet — Cisco notes the attack surface shrinks significantly when it is not.
  3. Check for compromise now: in FMC expert mode, run cat /var/log/messages | grep license. A line referencing /var/tmp/license.tmp via package_info.pl run as root is Cisco’s published indicator of exploitation.
  4. If the indicator is present, rotate all credentials, keys and certificates on the affected FMC device immediately and open a case with Cisco TAC for recovery guidance.

DIESEC Perspective

A CVSS 5.3 bug that Cisco itself rates “High” because it chains into a CVSS 10.0 bug is exactly the kind of vulnerability that patch-management programs relying purely on base scores keep missing. This is a management-plane story, not an appliance story — the same pattern that made Check Point SmartConsole worth a standalone warning less than a week earlier.

Not sure whether your Cisco Secure FMC deployment is internet-facing or running a patched build? Contact DIESEC for a rapid exposure assessment and patch verification across your firewall management infrastructure.

Sources: BleepingComputer | Cisco Security Advisory
Published: 2026-08-03 | Category: Vulnerabilities & Patches | ~4 min read