Cisco FMC hardcoded credential flaw actively exploited
Cisco disclosed that its Secure Firewall Management Center (FMC) software contains a hard‑coded low‑privilege account (static credentials) identified as CVE‑2026‑20316. The flaw lets an unauthenticated remote attacker log in to the FMC web interface and access sensitive data, and it can be chained with another FMC vulnerability (CVE‑2026‑20079) to obtain root privileges. Active exploitation was reported in July 2026, prompting Cisco to add the issue to the CISA Known Exploited Vulnerabilities catalog. Cisco issued hotfixes for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 and urged customers to apply them immediately, rotate all user credentials, cryptographic keys and certificates, and monitor logs for the indicator “/var/tmp/license.tmp”. Although the CVSS score is 5.3, Cisco assigned a High Security Impact Rating because of the potential for privilege escalation.
Entities: CISA · CVE-2026-20079 · CVE-2026-20316 · Cisco · Cisco Secure Firewall Management Center · Cisco Systems Inc. · VMware Inc. · vCenter Server
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 2 SOURCES] Cisco also patched a related vulnerability (CVE‑2026‑20079) that could bypass authentication and grant root access to the FMC.
- [● 3 SOURCES] A possible indicator of compromise is the presence of the file path “/var/tmp/license.tmp” in FMC logs.
- [● 3 SOURCES] Active exploitation of CVE‑2026‑20316 was first observed in July 2026.
- [● 3 SOURCES] Cisco recommends rotating all user credentials, cryptographic keys and certificates on affected FMC appliances after exploitation.
- [● 4 SOURCES] Cisco assigned a CVSS score of 5.3 but a High Security Impact Rating because the flaw can be chained with other vulnerabilities for privilege escalation.
- [● 4 SOURCES] Cisco Secure Firewall Management Center contains a hardcoded low‑privilege account (static credentials).
- [● 3 SOURCES] Cisco released hotfixes for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 to remediate the vulnerability.
- [● 4 SOURCES] The flaw (CVE‑2026‑20316) enables an unauthenticated remote attacker to log in to the FMC web interface and view sensitive data.