Updated September 20, 2026. Cisco’s September 16 advisories replace the earlier FMC hotfix tables with security hardening releases. Talos has also documented three intrusion clusters, including one that used static credentials to reach internal systems and deploy Qilin ransomware. Check both CVE-2026-20316 and CVE-2026-20079, then separate installing a fixed release from investigating an appliance that may already be compromised. [1] [3] [4]
Cisco says attackers are actively exploiting CVE-2026-20316, a static-credential vulnerability in on-premises Secure Firewall Management Center (FMC). The credential provides remote, unauthenticated access to a low-privileged account and can expose sensitive data. Because Cisco says the access can be chained with other FMC flaws, administrators should install an appropriate fixed release now and check the appliance for the confirmed /var/tmp/license.tmp log clue.
Cisco published the advisory on July 29, 2026. CISA added the issue to its Known Exploited Vulnerabilities catalog the same day and set an August 1 deadline for covered US federal agencies. [2] The CVSS base score is 5.3, but Cisco rates the issue High because exploitation is active and the foothold can support privilege escalation through a separate FMC vulnerability.
Which products does CVE-2026-20316 affect?
- On-premises Cisco Secure FMC Software: Affected regardless of device configuration. Upgrade to the fixed release for the deployed software track.
- Cloud-Delivered FMC (cdFMC): Confirmed not affected.
- Firewall Device Manager (FDM): Confirmed not affected.
- Secure Firewall ASA and FTD Software: Confirmed not affected by this CVE. Do not patch ASA or FTD as a substitute for updating FMC.
- Security Cloud Control (SCC): Confirmed not affected.
Keeping the FMC management interface off the public internet reduces the attack surface, but it does not remove the static credential or replace the security update. Internal access, exposed management networks, and a previously compromised host can still matter.
What Talos found after attackers entered FMC
CVE-2026-20079 is a separate authentication bypass that permits unauthenticated root access through script execution. CVE-2026-20316 exposes a low-privileged account; subsequent actions must be assessed separately. [4]
Talos’s September 9 investigation describes separate operations, not one universal attack chain. UAT-12197 exploited the authentication bypass, planted a web shell and used a Java command executor to retrieve credentials from internal databases.
UAT-11823 used both vulnerabilities and deployed Cyclops Blink. Talos assesses an overlap in tooling with Sandworm. A malicious license.tmp package was processed by the legitimate package_info.pl utility as root; the attackers also collected managed-device configurations.
UAT-11988 entered with static credentials, mapped the internal network and stole credentials. SOCKS5 and reverse-SSH tunnels extended access from FMC toward internal services before Qilin encrypted selected endpoints. That sequence explains why a low-privileged foothold on the management appliance can become a wider incident. [3]
Current fixed FMC releases
Cisco’s September 16 tables list these first fixed releases for both vulnerabilities. They supersede the old hotfix table and include additional hardening. Choose the appropriate supported release for your hardware and upgrade path; these are minimum fixed builds, not a claim that each is the latest available version. [1] [4]
- 7.0 and earlier:
7.0.10 - 7.2:
7.2.12 - 7.4:
7.4.8 - 7.6:
7.6.6 - 7.7:
7.7.13 - 10.0:
10.0.2 - 10.1:
10.1.0
The product exclusions above apply to CVE-2026-20316. Cisco’s separate CVE-2026-20079 advisory also lists SCC Firewall Management as affected, but says Cisco has deployed the SaaS fix and no user action is required there. Use the advisory for each CVE rather than carrying exclusions across them. Neither advisory offers a workaround that replaces a fixed release.
How to check for possible exploitation
From the FMC CLI, enter expert mode with the administrative privileges needed to read system logs and run zgrep "package_info.*license" /var/log/messages*. This searches current and rotated message logs. Cisco says a matching log entry that invokes /usr/local/sf/bin/package_info.pl with /var/tmp/license.tmp may indicate exploitation.
The string is a triage clue, not a complete verdict. Its absence does not prove the appliance was never accessed, and its presence should not be treated as attribution to a specific actor. Preserve the relevant logs before changing the system and contact Cisco TAC for recovery guidance when the clue appears or other suspicious access is found.
What administrators should do now
- Inventory every Secure FMC appliance. Record the on-premises release, management-interface exposure, and the firewalls it controls.
- Restrict management access. Remove direct internet exposure and limit the interface to trusted administrative networks while patching.
- Preserve and review logs. Search for the confirmed
/var/tmp/license.tmpclue and retain authentication, configuration, and network telemetry around suspicious events. - Install the appropriate hardening release. Check Cisco’s current advisory and supported upgrade path, then verify the installed build.
- Escalate suspected compromise. Contact Cisco TAC. Follow TAC’s recovery guidance before treating the appliance as trusted. Include potentially exposed credentials, keys and certificates in the recovery assessment; replace compromised secrets from a trusted environment.
- Review downstream trust. Check for unexpected policy, user, certificate, key, integration, or managed-device changes. A patched FMC does not invalidate secrets that may already have been copied.
The practical distinction matters: CVE-2026-20316 opens a low-privileged account; it is not itself a documented one-step root exploit. Administrators should still treat it urgently because the affected appliance stores sensitive management data and the access can be chained with other FMC vulnerabilities.
For related response patterns, see the Cisco Catalyst SD-WAN exploited-flaw guidance and the Check Point SmartConsole CVE-2026-16232 checklist.
References
- Cisco Product Security Incident Response Team. “Cisco Secure Firewall Management Center Software Static Credential Vulnerability.” Cisco Security Advisory, July 29, 2026; updated September 16, 2026. advisory and fixed releases.
- Cybersecurity and Infrastructure Security Agency. “CISA Adds One Known Exploited Vulnerability to Catalog.” CISA, July 29, 2026. KEV notice.
- Cisco Talos. “Active exploitation of Cisco Secure Firewall Management Center vulnerabilities.” September 9, 2026; updated September 10. investigation of three intrusion clusters.
- Cisco PSIRT. “Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability.” Updated September 16, 2026; accessed September 20. CVE-2026-20079 advisory.

