<- ALL CYBER NEWS

High

Cisco, FMC, Firewall, CVE-2026-20316, KEV, Zero-Day, Static Credentials

Cisco FMC CVE-2026-20316: Static-Credential Zero-Day Now in CISA KEV

Cisco FMC CVE-2026-20316 is a static-credentials zero-day exploited in the wild and added to CISA KEV on July 29, 2026. Affected versions, IoCs, and hotfixes.

Cisco FMC CVE-2026-20316: Static-Credential Zero-Day Now in CISA KEV

Cisco FMC CVE-2026-20316 is a static-credentials flaw in Cisco Secure Firewall Management Center that let unauthenticated attackers log in with a hidden low-privilege account — and it was exploited as a zero-day before a patch existed, landing in CISA's Known Exploited Vulnerabilities catalog on July 29, 2026 with a federal patch deadline of August 1. Its CVSS score is only 5.3, but that number badly undersells the risk: on a device that manages an organization's firewalls, even low-privileged access is a launch pad, and Cisco assigned the bug a High Security Impact Rating precisely because it can be chained to escalate privileges.

The flaw (CWE-259, use of hard-coded credentials) exists because Cisco Secure Firewall Management Center shipped a static user account whose credentials are the same on every install. An unauthenticated remote attacker who reaches the FMC interface can log in with that account and read sensitive data — and Cisco confirmed the account was used in active in-the-wild attacks earlier in July, which is what moved CISA to add it to KEV. Affected releases are FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, and Cisco has published hotfix builds for each: 7.0.9.1-3, 7.2.11.1-4, 7.4.7.1-3, 7.6.5.1-2, 7.7.12.1-2 and 10.0.1.1-2.

Why does a CVSS 5.3 flaw warrant an emergency KEV deadline?

Because CVSS scores the initial access, not the blast radius. The score is 5.3 because the built-in account is low-privileged — but the community's objection, aired loudly on r/netsec and infosec Twitter, is that low-privilege access on the control plane of your entire firewall estate is catastrophic the moment it is chained with a local privilege-escalation bug. That is exactly the chaining path Cisco's High Security Impact Rating warns about. The broader outrage is about vendor hygiene: a security vendor shipping hard-coded credentials on a security appliance in 2026 is the kind of own-goal that erodes trust, and CISA's three-day federal deadline forced teams to patch production firewalls with no normal testing window.

Attribute

Detail

CVE

CVE-2026-20316

CVSS / CWE

5.3 (Medium) / CWE-259 hard-coded credentials

KEV status

Added July 29, 2026; federal deadline August 1, 2026

Exploited in the wild

Yes — zero-day, confirmed by Cisco

Affected

Secure FMC 7.0, 7.2, 7.4, 7.6, 7.7, 10.0

Fixed

7.0.9.1-3, 7.2.11.1-4, 7.4.7.1-3, 7.6.5.1-2, 7.7.12.1-2, 10.0.1.1-2

How do I check whether my FMC was already accessed?

This is the top question defenders are asking, because the flaw was exploited before disclosure. Admins on the Cisco community are inspecting FMC logs in expert mode for references to the primary indicator (/var/tmp/license.tmp) — for example grepping /var/log/messages for license-related activity — and reviewing authentication logs for logins from the static account. The reassuring operational answer to the second-most-asked question: applying the FMC hotfix reboots the management plane out of band and does not interrupt active data-plane traffic on managed Firepower/FTD appliances. The third question is the uncomfortable one — why was the FMC management interface reachable from untrusted subnets at all — and the fix is to lock it to an out-of-band management network with strict ACLs.

Our read

This is a textbook case of why continuous verification beats a point-in-time score. A once-a-year pentest scheduled for Q4 would never have flagged a vendor-shipped static credential, and the CVSS number would have sorted it below dozens of "scarier" 9.8s in a patch queue — yet this is the one being exploited right now. Across 2025's actively exploited vulnerabilities, 67% would have been missed by an annual pentest, and 20% were exploited on or before the day they were disclosed. Prioritizing by "is it in KEV / is there a public exploit," not by CVSS alone, is the difference between patching this firewall today and finding out from an incident.

Reporting by The Hacker News and BleepingComputer; KEV listing per CISA; CVSS and CWE per NVD. Sources linked above.

Related: VMware CVE-2026-59309: vCenter auth bypass and VM escape · What CVSS and EPSS miss for patch prioritization

Frequently asked questions

Is CVE-2026-20316 actively exploited?
Yes. Cisco confirmed zero-day exploitation before a patch was available, and CISA added it to the KEV catalog on July 29, 2026 with an August 1 remediation deadline for federal agencies.

Why is the CVSS score only 5.3 if it's this urgent?
CVSS reflects that the hard-coded account is low-privileged and only reads data on its own. It does not account for chaining with a privilege-escalation flaw on a core firewall-management device, which is why Cisco rated the real-world impact "High."

Will patching drop my firewall traffic?
No. The FMC hotfix restarts the management plane out of band; active data-plane traffic on managed Firepower/FTD threat-defense appliances is not interrupted.

What's the main indicator of compromise?
References to /var/tmp/license.tmp in FMC logs, plus any authentication from the built-in low-privilege account. Review /var/log/messages and auth logs in expert mode, and restrict the management interface to an out-of-band network.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.