
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center (FMC) flaw, tracked as CVE-2026-20316 (CVSS score of 5.3), to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2026-20316 is a static credential vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to authenticate using a built-in low-privileged account and access sensitive information stored on the affected system.
“A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.” reads the advisory. “A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.”
The flaw stems from the presence of hardcoded credentials for a low-privileged user account. Although the account provides limited access, it could be combined with other Cisco Secure FMC Software vulnerabilities to achieve privilege escalation. The attack surface is reduced if the FMC management interface is not exposed to the public internet.
Cisco released the following hot fixes to address this issue:
| Cisco Secure FMC Software Release | Hot Fix Name |
|---|---|
| 7.0 | Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar |
| 7.2 | Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar |
| 7.4 | Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar |
| 7.6 | Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar |
| 7.7 | Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar |
| 10.0 | Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar |
Cisco confirmed active exploitation of the vulnerability in July 2026 and strongly urges customers to upgrade to a fixed software release immediately.
“In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” states the advisory.
Administrators can check for exploitation by running cat /var/log/messages | grep license in expert mode. If the logs contain references to /var/tmp/license.tmp, the device may have been compromised. Cisco advises organizations that suspect exploitation to contact TAC for recovery assistance and immediately rotate all user credentials, cryptographic keys, and certificates, as the vulnerability has been actively exploited.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerability by the end of this week, on August 1st, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)



