Cisco Secure FMC && hard-coded password exploited in Zero-Day attacks
Cisco Secure FMC && hard-coded password exploited in Zero-Day attacks
Summary
A critical vulnerability in the Cisco Secure Firewall Management Center (FMC) Software has been identified, allowing unauthenticated, remote attackers to exploit static credentials to gain unauthorized access to affected systems. This vulnerability, tracked as CVE-2026-20316, has been actively exploited in zero-day attacks.
Affected Systems and/or Applications
- Cisco Secure Firewall Management Center (FMC) Software
- The vulnerabilities do not impact:
- Cloud-Delivered FMC
- Firewall Device Manager
- Secure Firewall ASA Software
- Secure Firewall Threat Defense Software
- Security Cloud Control
Technical Details
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Mitigation
- Software Updates: Cisco has released hot fixes for Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Users are strongly advised to apply these updates immediately.
- Detection: Administrators should review the
/var/log/messageslog file for signs of exploitation, specifically looking for entries containing/var/tmp/license.tmp. - Response: If compromised, rotate all user credentials, keys, and certificates on the affected FMC device.
- Network Configuration: Reduce attack surface by ensuring the FMC management interface is not exposed to the public internet.
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation. This advisory will be updated if required.
References
- Cisco Security Advisory: Cisco Secure FMC Static Credential Vulnerability
- CISA Alert: CISA Adds One Known Exploited Vulnerability to Catalog (Note: Article not fetched)

.avif)




.webp)