Cisco warns of FMC static credential flaw exploited in zero-day attacks
July 29, 2026 · BleepingComputer · Severity: CRITICAL
Cisco has issued an emergency warning that a high-severity static credential vulnerability in Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, is being actively exploited in zero-day attacks. The flaw stems from hardcoded credentials for a low-privilege account in Cisco Secure FMC Software, allowing unauthenticated remote attackers to log in and access sensitive data. Although the vulnerability carries a CVSS score of 5.3, Cisco assigned a High severity rating because the initial access can be chained with other FMC flaws to escalate privileges. Cisco has released hot fixes for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0, with no workarounds available. Separately, Cisco also updated an advisory for CVE-2026-20079, a critical authentication bypass vulnerability (CVSS 10.0) affecting the same product line, and published indicators of compromise involving /var/tmp/license.tmp log entries.
Key Takeaways
- Static credentials in FMC enable zero-day access — CVE-2026-20316 uses hardcoded credentials for a low-privilege account, allowing unauthenticated remote logins to FMC devices.
- Chained with other flaws for privilege escalation — Despite a 5.3 CVSS base score, Cisco rates it High severity because it can be combined with other FMC vulnerabilities to gain full administrative control. Hot fixes available, no workarounds — Cisco has patched FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 — administrators must install these fixes as there are no mitigations.
- Critical auth bypass also patched — CVE-2026-20079 (CVSS 10.0) allows unauthenticated remote attackers to bypass authentication and execute commands as root on FMC devices.