CVE-2026-20316 is a static credential vulnerability affecting the web interface of Cisco Secure Firewall Management Center (FMC) Software.
The vulnerability is caused by the presence of static credentials associated with a low-privileged account. An attacker who obtains or uses these credentials can authenticate to an affected FMC system and access sensitive information available to that account.
Cisco PSIRT has confirmed active exploitation of CVE-2026-20316 during July 2026, and CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations should immediately apply the appropriate Cisco hotfix and investigate affected systems for signs of compromise.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Identifier: CVE-2026-20316
PoC or Exploitation:
Cisco PSIRT confirmed that CVE-2026-20316 was actively exploited in the wild during July 2026. CISA added the vulnerability to the Known Exploited Vulnerabilities Catalog.
CVSS Score: 5.3 (Medium, CVSS v3.1)
Update / Patch:
Cisco has released hotfixes for affected Cisco Secure Firewall Management Center branches. There are no workarounds that address this vulnerability.
Cisco released the following hotfixes:
- Cisco Secure FMC 7.0:
Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar
- Cisco Secure FMC 7.2:
Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar
- Cisco Secure FMC 7.4:
Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar
- Cisco Secure FMC 7.6:
Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar
- Cisco Secure FMC 7.7:
Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar
- Cisco Secure FMC 10.0:
Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar
Cisco advisory and update guidance:
Description:
CVE-2026-20316 is a static-credential vulnerability in the web interface of Cisco Secure Firewall Management Center Software.
The vulnerability is caused by static credentials associated with a low-privileged account. An attacker who uses these credentials can log in to an affected FMC system and access sensitive information available to that account.
Mitigation Recommendation:
Apply the Cisco hotfix corresponding to the affected FMC release immediately. There is no vendor-provided workaround.
Restrict access to the FMC management interface to trusted administrative networks.
To determine whether the vulnerability may have been exploited, run the following command in expert mode:
cat /var/log/messages | grep license
A matching log entry that references /var/tmp/license.tmp may indicate exploitation.
If exploitation is suspected, contact Cisco TAC for recovery assistance. At a minimum, Cisco recommends rotating all user credentials, keys, and certificates on the affected FMC device because active exploitation has been ongoing.
Review the affected system for unauthorized access to sensitive information and for evidence that CVE-2026-20316 was chained with another FMC vulnerability.