Protect.Computer
NEWS

Cisco FMC Zero-Day: Hardcoded Credentials Under Active Attack

· 1 min read · Got hacked Network safety
Cisco FMC Zero-Day: Hardcoded Credentials Under Active Attack

Cisco has disclosed two serious vulnerabilities in its Secure Firewall Management Center (FMC) software and confirmed that one of them is being actively exploited in the wild as a zero-day. CVE-2026-20316 is a static-credential flaw: the software ships with a hardcoded built-in account whose credentials are fixed and cannot be changed by administrators. An unauthenticated attacker reachable over the network can log in using those credentials, access sensitive firewall configuration data, and chain the access with other vulnerabilities to escalate privileges further. Cisco discovered the in-the-wild exploitation in July 2026.

The second vulnerability, CVE-2026-20079, is separate and carries a CVSS score of 10.0 — the maximum. It lets an unauthenticated remote attacker bypass authentication entirely and execute arbitrary scripts and commands as root on the FMC appliance. Cisco updated its advisory for this flaw on July 29 and has released hot fixes for both issues across all affected versions. There are no workarounds for CVE-2026-20316, making patching the only path to remediation. As an indicator of compromise for both vulnerabilities, Cisco advises checking /var/log/messages for entries referencing /var/tmp/license.tmp.

How to check if you’re affected

Affected versions of Cisco Secure Firewall Management Center (FMC) Software include 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cloud-Delivered FMC, Firewall Device Manager, Cisco Secure Firewall ASA Software, Cisco Threat Defense Software, and Security Cloud Control are not affected. Check your FMC version in the web interface under Help → About, then apply the hot fix corresponding to your release from Cisco’s Security Advisory. Priority should be given to systems exposed to untrusted networks.

Sources

Related reading