CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Cisco FMC Zero-Day CVE-2026-20316 Actively Exploited: Static Credentials Expose Sensitive Data

July 30, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed security flaw, CVE-2026-20316, impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog following reports of zero-day exploitation. This vulnerability, with a CVSS score of 5.3, allows an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data. Cisco attributed the flaw to the presence of static user credentials for a low-privileged account. The attack surface is reduced if the FMC management interface lacks public internet access. Cisco assigned a Security Impact Rating (SIR) of High due to the potential for chaining with other Cisco Secure FMC Software vulnerabilities to elevate privileges. Security researcher Jimi Sebree of Horizon3.ai discovered and reported the flaw. Cisco acknowledged active exploitation earlier this month but did not disclose attack origins or methods. Hot fixes are available for versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Indicators of compromise include the presence of /var/tmp/license.tmp in the output of the ‘cat /var/log/messages | grep license’ CLI command. Cisco also updated its advisory for CVE-2026-20079, a critical authentication bypass flaw with a CVSS score of 10.0, to include the same indicators and hot fixes, though no malicious exploitation of that vulnerability is known. Federal Civilian Executive Branch (FCEB) agencies must apply fixes by August 1, 2026.

CVEs: CVE-2026-20316, CVE-2026-20079, CVE-2026-50522

Companies: Cisco, Horizon3.ai

Products: Cisco Secure Firewall Management Center