Cisco FMC CVE-2026-20316: patch your firewall manager
Cisco shipped hotfixes for a static-credential zero-day in Secure Firewall Management Center, already exploited and in CISA KEV. No workaround. Rotate credentials too.
Cisco published advisory cisco-sa-fmc-static-cred-BET3Cjh on July 29 for CVE-2026-20316, a static-credential flaw in Secure Firewall Management Center. Cisco's PSIRT says it was already being exploited when the advisory shipped. CISA added it to the Known Exploited Vulnerabilities catalog the same day with an August 1 remediation deadline for federal civilian agencies. There is no workaround — only a hotfix. If someone manages Cisco firewalls for you, this CVE-2026-20316 patch is a today problem.
What actually happened
FMC ships with static credentials for a built-in low-privilege account. Per BleepingComputer, an unauthenticated remote attacker can use them to log into the web interface and read whatever that account can see. The CVSS base score is only 5.3 — Cisco rated it High anyway, because that foothold chains with other FMC bugs to escalate privileges.
Hotfixes are out for FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cloud-delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense, and Security Cloud Control are not affected.
The part most coverage buries: Cisco tells you to rotate every user credential, key, and certificate on the FMC device, because exploitation has been ongoing. Patching alone doesn't undo access someone already took. Help Net Security also flags an indicator of compromise worth grepping for: execution of package_info.pl referencing /var/tmp/license.tmp in system logs.
Why a firewall management flaw matters for your business
FMC isn't a firewall. It's the console that configures every firewall you own — rules, VPN config, the policies deciding what reaches your servers. An attacker reading that console gets your network map without touching a single protected system.
Small businesses rarely run FMC in-house. Your MSP or IT contractor does, often on one shared appliance across their whole client book. That's the exposure: you are one tenant on a box that just had a published zero-day, and you will not get an email about it.
So ask, in writing, and ask this week. Which FMC version are you on, was the hotfix applied, and were credentials, keys, and certificates rotated afterward? Then the question that matters most: is the FMC management interface reachable from the public internet? Cisco notes the attack surface shrinks considerably when it isn't. A firewall console belongs behind a VPN, full stop. If the answer is "we'd have to check," that's the finding.
Key takeaways
- CVE-2026-20316 is a static-credential flaw in Cisco Secure FMC, exploited in the wild before the July 29 advisory
- CVSS 5.3 but rated High by Cisco — it chains with other FMC bugs for privilege escalation
- In CISA KEV as of July 29 with an August 1 federal deadline; hotfixes for 7.0, 7.2, 7.4, 7.6, 7.7, 10.0; no workaround
- Cloud-delivered FMC, FDM, ASA, Threat Defense, and Security Cloud Control are unaffected
- Patching is not enough — Cisco says rotate all credentials, keys, and certificates on the device, and get the management interface off the public internet
You don't manage the box, but you own the blast radius. We audit what your IT vendor exposes to the internet, put management interfaces behind a VPN, and give you a patch-and-rotate checklist you can actually hold them to. Book an exposure review.
Sources: Cisco, BleepingComputer, Help Net Security.
- #cisco
- #cve-2026-20316
- #firewall
- #security
- #patching
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
North Korea behind the debug and chalk npm hijacks
Amazon links the debug, chalk, and axios npm supply chain attacks to a DPRK group. One incident hit 1 in 10 cloud environments in two hours. Audit your dependencies.
Read itExchange OWA CVE-2026-42897: patch your mail server
Russian actor TA488 is exploiting CVE-2026-42897 in Outlook Web Access to drop the OWAReaper backdoor. It survives password resets. On-prem Exchange only.
Read it