A newly disclosed security vulnerability in Cisco Secure Firewall Management Center (FMC) Software is being actively exploited, prompting U.S. cybersecurity authorities to issue urgent warnings and recommend immediate updates.
The vulnerability, tracked as CVE-2026-20316, has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog after reports confirmed that attackers are using the flaw in real-world attacks.
Flaw Allows Unauthorized Access Through Hidden Credentials
Cisco said the vulnerability exists because certain affected FMC systems contain static credentials tied to a low-privileged user account. An unauthenticated remote attacker could exploit the issue by using those credentials to access an impacted device.
Successful exploitation could allow attackers to log in as the low-privileged user and view sensitive information stored within the affected system.
Although the vulnerability has a CVSS severity score of 5.3, Cisco classified its security impact as High because attackers could potentially combine it with other vulnerabilities to gain additional privileges.
Cisco also noted that the risk is reduced when the FMC management interface is not exposed to the public internet.
Security Researchers Identify Active Exploitation
The vulnerability was discovered and reported by Jimi Sebree, a security researcher at Horizon3.ai. Cisco confirmed that exploitation began earlier in July but has not disclosed details about the attackers, their objectives, or the exact methods used in ongoing campaigns.
The company is urging customers to apply available hotfixes for affected FMC software versions as soon as possible.
Cisco Releases Emergency Fixes
Cisco has released hotfix updates addressing CVE-2026-20316 across multiple Secure Firewall Management Center versions, including:
- FMC Software 7.0
- FMC Software 7.2
- FMC Software 7.4
- FMC Software 7.6
- FMC Software 7.7
- FMC Software 10.0
Organizations using affected versions are advised to install the appropriate security updates and review their systems for signs of compromise.
Cisco Provides Detection Guidance
Cisco has provided an indicator of compromise that administrators can use to check whether their systems may have been targeted.
Customers can run the following command in expert mode:
cat /var/log/messages | grep license
If the output contains a reference to:
/var/tmp/license.tmp
Cisco said there may be evidence that the vulnerability was exploited.
The company provided an example log entry showing suspicious activity involving the temporary file location.
Potential Connection to Critical Authentication Bypass Bug
Cisco has also updated its advisory for another serious vulnerability, CVE-2026-20079, a critical authentication bypass flaw affecting Secure FMC Software.
The update adds another bug identifier, additional indicators of compromise, and related hotfix information. While Cisco said it has not confirmed exploitation of CVE-2026-20079, security experts warn that attackers could potentially combine it with CVE-2026-20316 to achieve deeper system access.
CVE-2026-20079 carries a maximum CVSS score of 10.0 and could allow attackers to execute unauthorized scripts and obtain root-level access.
Federal Agencies Urged to Patch Immediately
Due to active exploitation, federal civilian agencies have been instructed to apply the available fixes by August 1, 2026.
Security experts recommend that all organizations using Cisco Secure Firewall Management Center review their deployments, restrict management interfaces from public exposure, apply patches, and investigate logs for possible unauthorized activity.