Cisco FMC CVE-2026-20316 Exploited: Check and Patch

Brendan Smith
Brendan Smith - Cybersecurity Analyst
5 Min Read
A steel firewall management vault is opened by a glowing static password key beside the CVE-2026-20316 identifier.
The exploited Cisco Secure FMC flaw uses a static credential and may leave a license-log clue on affected appliances.

Cisco says attackers are actively exploiting CVE-2026-20316, a static-credential vulnerability in on-premises Secure Firewall Management Center (FMC). The credential provides remote, unauthenticated access to a low-privileged account and can expose sensitive data. Because Cisco says the access can be chained with other FMC flaws, administrators should install the release-specific hotfix now and check the appliance for the confirmed /var/tmp/license.tmp log clue.

Cisco published the advisory on July 29, 2026. CISA added the issue to its Known Exploited Vulnerabilities catalog the same day and set an August 1 deadline for covered US federal agencies. The CVSS base score is 5.3, but Cisco rates the issue High because exploitation is active and the foothold can support privilege escalation through a separate FMC vulnerability.

Which Cisco products are affected?

Product or deployment Status and action
On-premises Cisco Secure FMC Software Affected regardless of device configuration. Install the hotfix for the exact release.
Cloud-Delivered FMC (cdFMC) Confirmed not affected.
Firewall Device Manager (FDM) Confirmed not affected.
Secure Firewall ASA and FTD Software Confirmed not affected by this CVE. Do not patch ASA or FTD as a substitute for updating FMC.
Security Cloud Control (SCC) Confirmed not affected.

Keeping the FMC management interface off the public internet reduces the attack surface, but it does not remove the static credential or replace the hotfix. Internal access, exposed management networks, and a previously compromised host can still matter.

Hotfixes for CVE-2026-20316

Secure FMC release Cisco hotfix
7.0 Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar
7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar
7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar
7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar
7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar
10.0 Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar

Cisco lists no workaround. Restricting management access is a useful containment measure, but full remediation requires the vendor hotfix. Verify the downloaded package and installation instructions through the Cisco Software Center rather than using a filename copied from an unofficial mirror.

How to check for possible exploitation

From the FMC CLI, enter expert mode and run cat /var/log/messages | grep license. Cisco says a matching log entry that invokes /usr/local/sf/bin/package_info.pl with /var/tmp/license.tmp may indicate exploitation.

The string is a triage clue, not a complete verdict. Its absence does not prove the appliance was never accessed, and its presence should not be treated as attribution to a specific actor. Preserve the relevant logs before changing the system and contact Cisco TAC for recovery guidance when the clue appears or other suspicious access is found.

What administrators should do now

  1. Inventory every Secure FMC appliance. Record the on-premises release, management-interface exposure, and the firewalls it controls.
  2. Restrict management access. Remove direct internet exposure and limit the interface to trusted administrative networks while patching.
  3. Preserve and review logs. Search for the confirmed /var/tmp/license.tmp clue and retain authentication, configuration, and network telemetry around suspicious events.
  4. Install the exact Cisco hotfix. Use the Software Center package for the deployed release and verify that the fix completed successfully.
  5. Escalate suspected compromise. Contact Cisco TAC. Cisco recommends rotating all user credentials, keys, and certificates on the FMC when exploitation is suspected because active exploitation has been ongoing.
  6. Review downstream trust. Check for unexpected policy, user, certificate, key, integration, or managed-device changes. A patched FMC does not invalidate secrets that may already have been copied.

The practical distinction matters: CVE-2026-20316 opens a low-privileged account; it is not itself a documented one-step root exploit. Administrators should still treat it urgently because the affected appliance stores sensitive management data and the access can be chained with other FMC vulnerabilities.

For related response patterns, see the Cisco Catalyst SD-WAN exploited-flaw guidance and the Check Point SmartConsole CVE-2026-16232 checklist.

References

  1. Cisco Product Security Incident Response Team. “Cisco Secure Firewall Management Center Software Static Credential Vulnerability.” Cisco Security Advisory, July 29, 2026. advisory and hotfix table.
  2. Cybersecurity and Infrastructure Security Agency. “CISA Adds One Known Exploited Vulnerability to Catalog.” CISA, July 29, 2026. KEV notice.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?