Cisco says attackers have been using a flaw in Secure Firewall Management Center to get unauthorized access to vulnerable management systems. The zero-day, CVE-2026-20316, is caused by built-in static credentials for a low-privilege account and affects Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0; Cisco released hotfixes, said there are no workarounds, and published a /var/tmp/license.tmp log indicator that may show compromise. Cisco also updated guidance for separate critical FMC auth-bypass CVE-2026-20079, but said it is not aware of exploitation of that bug.
Why it matters: Organizations using on-premises Cisco Secure FMC should treat this as urgent because attackers are already using it and Cisco says it can be chained with other bugs for deeper access. Install the hotfixes immediately, review the listed logs for compromise, and rotate credentials, keys, and certificates if affected systems show the indicator.
Eduard Kovacs
2026.07.30
98% relevant
This article is a direct update on the same event, adding that Cisco released patches for the actively exploited zero-day, described it as a static-credential issue enabling unauthenticated login to a low-privilege account, said exploitation was seen in July, and noted CISA added the flaw to KEV with an August 1 deadline for federal agencies.
info@thehackernews.com (The Hacker News)
2026.07.30
98% relevant
This is the same underlying event: active exploitation of Cisco Secure Firewall Management Center zero-day CVE-2026-20316. The article reinforces that the bug involves static credentials and could expose sensitive data, updating defenders on impact and urgency.
Lawrence Abrams
2026.07.29
100% relevant
This article appears to establish a distinct new tracked event: active zero-day exploitation of Cisco Secure FMC static credentials flaw CVE-2026-20316, alongside updated Cisco guidance for related FMC bug CVE-2026-20079.
← Back to all stories