Skip to content
Rush Commerce
Software & Dev3 min read

Cisco FMC CVE-2026-20316: patch your firewall manager

Cisco shipped hotfixes for a static-credential zero-day in Secure Firewall Management Center, already exploited and in CISA KEV. No workaround. Rotate credentials too.

Cisco published advisory cisco-sa-fmc-static-cred-BET3Cjh on July 29 for CVE-2026-20316, a static-credential flaw in Secure Firewall Management Center. Cisco's PSIRT says it was already being exploited when the advisory shipped. CISA added it to the Known Exploited Vulnerabilities catalog the same day with an August 1 remediation deadline for federal civilian agencies. There is no workaround — only a hotfix. If someone manages Cisco firewalls for you, this CVE-2026-20316 patch is a today problem.

What actually happened

FMC ships with static credentials for a built-in low-privilege account. Per BleepingComputer, an unauthenticated remote attacker can use them to log into the web interface and read whatever that account can see. The CVSS base score is only 5.3 — Cisco rated it High anyway, because that foothold chains with other FMC bugs to escalate privileges.

Hotfixes are out for FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Cloud-delivered FMC, Firewall Device Manager, Secure Firewall ASA, Secure Firewall Threat Defense, and Security Cloud Control are not affected.

The part most coverage buries: Cisco tells you to rotate every user credential, key, and certificate on the FMC device, because exploitation has been ongoing. Patching alone doesn't undo access someone already took. Help Net Security also flags an indicator of compromise worth grepping for: execution of package_info.pl referencing /var/tmp/license.tmp in system logs.

Why a firewall management flaw matters for your business

FMC isn't a firewall. It's the console that configures every firewall you own — rules, VPN config, the policies deciding what reaches your servers. An attacker reading that console gets your network map without touching a single protected system.

Small businesses rarely run FMC in-house. Your MSP or IT contractor does, often on one shared appliance across their whole client book. That's the exposure: you are one tenant on a box that just had a published zero-day, and you will not get an email about it.

So ask, in writing, and ask this week. Which FMC version are you on, was the hotfix applied, and were credentials, keys, and certificates rotated afterward? Then the question that matters most: is the FMC management interface reachable from the public internet? Cisco notes the attack surface shrinks considerably when it isn't. A firewall console belongs behind a VPN, full stop. If the answer is "we'd have to check," that's the finding.

Key takeaways

  • CVE-2026-20316 is a static-credential flaw in Cisco Secure FMC, exploited in the wild before the July 29 advisory
  • CVSS 5.3 but rated High by Cisco — it chains with other FMC bugs for privilege escalation
  • In CISA KEV as of July 29 with an August 1 federal deadline; hotfixes for 7.0, 7.2, 7.4, 7.6, 7.7, 10.0; no workaround
  • Cloud-delivered FMC, FDM, ASA, Threat Defense, and Security Cloud Control are unaffected
  • Patching is not enough — Cisco says rotate all credentials, keys, and certificates on the device, and get the management interface off the public internet

You don't manage the box, but you own the blast radius. We audit what your IT vendor exposes to the internet, put management interfaces behind a VPN, and give you a patch-and-rotate checklist you can actually hold them to. Book an exposure review.

Sources: Cisco, BleepingComputer, Help Net Security.

  • #cisco
  • #cve-2026-20316
  • #firewall
  • #security
  • #patching
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.