CVE-2026-20316: Cisco Secure FMC Zero-Day Exploited
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed on July 29, 2026, allows a remote, unauthenticated attacker to log in to vulnerable systems using a built-in low-privilege account and access sensitive data.
Cisco said it detected active exploitation in July and has published indicators of compromise (IoCs) to help organizations identify potential attacks. The vulnerability was reported by Jimi Sebree of Horizon3.ai.
Static credentials expose Cisco Secure FMC systems
Cisco describes CVE-2026-20316 as a static credential vulnerability (CWE-259) caused by the presence of hardcoded credentials for a low-privilege account in the web interface of Cisco Secure FMC. A successful attack enables unauthorized access to sensitive information available to that account. Although the flaw carries a CVSS 3.1 base score of 5.3, Cisco assigned it a High Security Impact Rating because it can be chained with other Cisco Secure FMC vulnerabilities to achieve privilege escalation.
According to Cisco’s advisory, “If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.” However, the company stressed that no workarounds are available and urged customers to install the released hot fixes.
The vulnerability affects Cisco Secure FMC software regardless of device configuration. Cisco confirmed that Cloud-Delivered FMC (cdFMC), Firewall Device Manager (FDM), Secure Firewall ASA Software, Secure Firewall Threat Defense (FTD) Software, and Security Cloud Control (formerly Defense Orchestrator) are not affected.
Indicators of compromise and available hot fixes
Cisco provided IoCs to help identify potential exploitation of CVE-2026-20316. Administrators are advised to run cat /var/log/messages | grep license in expert mode. Log entries referencing /var/tmp/license.tmp may indicate compromise.
If exploitation is suspected, Cisco recommends contacting its Technical Assistance Center (TAC) and rotating all user credentials, cryptographic keys, and certificates on the affected Cisco Secure FMC device because exploitation has been ongoing.
The company released hot fixes for software releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cisco emphasized that upgrading to the fixed software is the only complete remediation for CVE-2026-20316.
CISA adds CVE-2026-20316 to KEV catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20316 to its Known Exploited Vulnerabilities (KEV) catalog on July 29, directing federal civilian agencies to remediate the issue by August 1.
While Cisco acknowledged ongoing exploitation and published IoCs, it has not disclosed details about the attacks observed in the wild, and no public reports describing the campaigns have emerged. Horizon3.ai has also not released technical details about the vulnerability.
Cisco additionally updated its advisory for CVE-2026-20079, a critical Cisco Secure FMC vulnerability originally patched in March. The latest disclosure follows several recent instances in which Cisco identified active exploitation targeting other products, including Catalyst SD-WAN Manager and Unified Communications Manager, highlighting the continued focus on securing enterprise networking infrastructure.
