Cisco Issues Hot Fixes as Static-Credential FMC Flaw Is Exploited

On July 29, 2026, CISA added Cisco Secure Firewall Management Center flaw CVE-2026-20316 to its Known Exploited Vulnerabilities catalog. The zero-day, rated 5.3 under CVSS, lets an unauthenticated remote attacker sign in with a static low-privilege account and access sensitive data.
Why a moderate score still carries high risk
Cisco assigned the flaw a High Security Impact Rating rather than Medium because attackers may chain it with other FMC vulnerabilities to elevate privileges. Exposure is lower when the FMC management interface is not accessible from the public internet, but isolation does not replace remediation.
Cisco said exploitation began in July, without identifying the operators, initial attack date or exact technique. Horizon3.ai researcher Jimi Sebree discovered and reported the vulnerability.
“A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.”
Hot fixes and compromise checks
Cisco released hot fixes for six branches: 7.0 with GB-7.0.9.1-3, 7.2 with HL-7.2.11.1-4, 7.4 with HG-7.4.7.1-3, 7.6 with CY-7.6.5.1-2, 7.7 with AM-7.7.12.1-2 and 10.0 with P-10.0.1.1-2. Federal Civilian Executive Branch agencies were instructed to apply fixes by August 1, 2026.
Administrators can run cat /var/log/messages | grep license in expert mode. A result containing /var/tmp/license.tmp may indicate exploitation, although the string alone is not definitive proof of compromise.
Cisco also updated its notice for CVE-2026-20079, a CVSS 10.0 authentication bypass, adding bug ID CSCwt95974, the same indicator and hot fixes. That flaw can execute arbitrary scripts as root, so the shared artifact suggests the two issues could be chained. Cisco has not observed malicious exploitation of CVE-2026-20079.
For businesses, the practical response is to remove FMC administration from public access, deploy the branch-specific hot fix, preserve logs and investigate the indicator. Because a low-privilege entry point may become part of a root-level chain, patch priority should reflect operational impact rather than the 5.3 score alone.

