Cisco says attackers are actively exploiting CVE-2026-20316, a static-credential vulnerability in on-premises Secure Firewall Management Center (FMC). The credential provides remote, unauthenticated access to a low-privileged account and can expose sensitive data. Because Cisco says the access can be chained with other FMC flaws, administrators should install the release-specific hotfix now and check the appliance for the confirmed /var/tmp/license.tmp log clue.
Cisco published the advisory on July 29, 2026. CISA added the issue to its Known Exploited Vulnerabilities catalog the same day and set an August 1 deadline for covered US federal agencies. The CVSS base score is 5.3, but Cisco rates the issue High because exploitation is active and the foothold can support privilege escalation through a separate FMC vulnerability.
Which Cisco products are affected?
| Product or deployment | Status and action |
|---|---|
| On-premises Cisco Secure FMC Software | Affected regardless of device configuration. Install the hotfix for the exact release. |
| Cloud-Delivered FMC (cdFMC) | Confirmed not affected. |
| Firewall Device Manager (FDM) | Confirmed not affected. |
| Secure Firewall ASA and FTD Software | Confirmed not affected by this CVE. Do not patch ASA or FTD as a substitute for updating FMC. |
| Security Cloud Control (SCC) | Confirmed not affected. |
Keeping the FMC management interface off the public internet reduces the attack surface, but it does not remove the static credential or replace the hotfix. Internal access, exposed management networks, and a previously compromised host can still matter.
Hotfixes for CVE-2026-20316
| Secure FMC release | Cisco hotfix |
|---|---|
| 7.0 | Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar |
| 7.2 | Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar |
| 7.4 | Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar |
| 7.6 | Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar |
| 7.7 | Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar |
| 10.0 | Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar |
Cisco lists no workaround. Restricting management access is a useful containment measure, but full remediation requires the vendor hotfix. Verify the downloaded package and installation instructions through the Cisco Software Center rather than using a filename copied from an unofficial mirror.
How to check for possible exploitation
From the FMC CLI, enter expert mode and run cat /var/log/messages | grep license. Cisco says a matching log entry that invokes /usr/local/sf/bin/package_info.pl with /var/tmp/license.tmp may indicate exploitation.
The string is a triage clue, not a complete verdict. Its absence does not prove the appliance was never accessed, and its presence should not be treated as attribution to a specific actor. Preserve the relevant logs before changing the system and contact Cisco TAC for recovery guidance when the clue appears or other suspicious access is found.
What administrators should do now
- Inventory every Secure FMC appliance. Record the on-premises release, management-interface exposure, and the firewalls it controls.
- Restrict management access. Remove direct internet exposure and limit the interface to trusted administrative networks while patching.
- Preserve and review logs. Search for the confirmed
/var/tmp/license.tmpclue and retain authentication, configuration, and network telemetry around suspicious events. - Install the exact Cisco hotfix. Use the Software Center package for the deployed release and verify that the fix completed successfully.
- Escalate suspected compromise. Contact Cisco TAC. Cisco recommends rotating all user credentials, keys, and certificates on the FMC when exploitation is suspected because active exploitation has been ongoing.
- Review downstream trust. Check for unexpected policy, user, certificate, key, integration, or managed-device changes. A patched FMC does not invalidate secrets that may already have been copied.
The practical distinction matters: CVE-2026-20316 opens a low-privileged account; it is not itself a documented one-step root exploit. Administrators should still treat it urgently because the affected appliance stores sensitive management data and the access can be chained with other FMC vulnerabilities.
For related response patterns, see the Cisco Catalyst SD-WAN exploited-flaw guidance and the Check Point SmartConsole CVE-2026-16232 checklist.
References
- Cisco Product Security Incident Response Team. “Cisco Secure Firewall Management Center Software Static Credential Vulnerability.” Cisco Security Advisory, July 29, 2026. advisory and hotfix table.
- Cybersecurity and Infrastructure Security Agency. “CISA Adds One Known Exploited Vulnerability to Catalog.” CISA, July 29, 2026. KEV notice.

