Cisco warns of FMC static credential flaw exploited in zero-day attacks

www.bleepingcomputer.com/news/secu…

Cisco disclosed that CVE-2026-20316, a static-credential vulnerability in Secure Firewall Management Center (FMC) Software, has been actively exploited in zero-day attacks. The flaw allows an unauthenticated remote attacker to log in with a built-in low-privilege account and access sensitive data. Although its CVSS score is 5.3, Cisco rated it High severity because it can be chained with other FMC flaws for privilege escalation.

Hotfixes are available for FMC releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. There are no workarounds. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with an August 1 remediation deadline for federal agencies. Organizations should also check logs for indicators such as references to /var/tmp/license.tmp and rotate credentials if compromise is suspected.

Edward Kiledjian @ekiledjian