CVE-2026-20316 — a Secure Firewall Management Center (FMC) static-credential flaw — was “actively exploited in zero-day attacks,” Cisco warned, after a low-privilege account with built-in static credentials allowed unauthenticated remote logins to vulnerable devices.
CVE-2026-20316: static credential access and why Cisco rates it “High”
Cisco says the vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. An unauthenticated, remote attacker can use those credentials to log in to an affected system and access sensitive data available to that account. Although CVE-2026-20316 carries a CVSS score of 5.3, Cisco assigned a High severity rating because that level of access can be combined with other FMC vulnerabilities to elevate privileges. The company has not identified the additional vulnerabilities or explained how they are being used in attacks.
Cisco also reported it became aware of active exploitation in July 2026 but has not shared when the attacks began, who is behind them, or which organizations were targeted. The initial report of the vulnerability was credited to Jimi Sebree of Horizon3.ai.
CVE-2026-20079: a separate critical authentication bypass and how it differs
Cisco updated an advisory for a separate, critical FMC authentication bypass tracked as CVE-2026-20079. This flaw, with a maximum CVSS score of 10.0, allows an unauthenticated, remote attacker to bypass authentication and execute scripts and commands as root by sending specially crafted HTTP requests to an affected FMC device. Cisco says the root cause is an improper system process created when the system boots.
CVE-2026-20079 was originally disclosed in March 2026; Cisco updated the advisory on July 29 to add a second bug ID, hot fixes, and indicators of compromise. Cisco says it is not aware of malicious exploitation of CVE-2026-20079. The company published the same /var/tmp/license.tmp indicator in both advisories but has not explained whether the vulnerabilities are connected. Cisco’s description of CVE-2026-20079 indicates it can be exploited without using the static credentials associated with CVE-2026-20316 to achieve root access.
Indicator of compromise: the /var/tmp/license.tmp log entry and how to find it
To detect whether an FMC installation was compromised, Cisco recommends administrators review the /var/log/messages log file for specific signs. The vendor provides the simple search command (to be run in expert mode):
- cat /var/log/messages | grep license
Cisco says a log entry containing /var/tmp/license.tmp may indicate compromise. The company published this example:
Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm
Cisco’s explanation: the entry shows the FMC web process, running under the www account, invoking Cisco's package_info.pl script as root and supplying the /var/tmp/license.tmp file. If a device contains this indicator of compromise, Cisco advises administrators to rotate all user credentials, keys, and certificates on the affected FMC device because exploitation has been ongoing, and to contact the Cisco TAC for assistance with recovery.
Hot fixes, affected products, and limitations of mitigations
Cisco has released hot fixes for Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. The vendor notes there are no workarounds that address CVE-2026-20316, and likewise says there are no workarounds that fully address CVE-2026-20079. Cisco also said the flaw affects Cisco Secure FMC Software regardless of device configuration, but does not impact Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, or Security Cloud Control.
Cisco added that the attack surface is reduced when the FMC management interface is not exposed to the public internet, a configuration detail teams can use to prioritize remediation and network segmentation while applying fixes.
What this means for technologists, affected enterprises, and incident responders
- Technologists and security teams: install the available hot fixes for the listed Secure FMC releases without delay; run the recommended log search for the /var/tmp/license.tmp indicator; and, if the IOC appears, rotate all user credentials, keys, and certificates on the affected FMC device as Cisco directs.
- Affected enterprises and procurement leaders: verify whether FMC management interfaces are publicly exposed and prioritize patching of the listed releases (7.0, 7.2, 7.4, 7.6, 7.7, 10.0); note that Cloud-Delivered FMC and several other Cisco firewall products are not affected by CVE-2026-20316 according to Cisco’s advisory.
- Incident responders and support teams: organizations that believe they are compromised should contact the Cisco TAC for recovery assistance, as Cisco recommends; be aware that Cisco has published the same /var/tmp/license.tmp indicator in both advisories but has not explained whether the two tracked vulnerabilities are connected.
Cisco’s advisories lay out a narrow technical trail — a static credential, an unusual log entry, and matching hot fixes — but leave a key question open: whether attackers are chaining the static-credential access (CVE-2026-20316) with the boot-time authentication bypass (CVE-2026-20079), or exploiting either independently. BleepingComputer contacted Cisco to clarify whether the vulnerabilities are connected, whether CVE-2026-20079 has been exploited, and whether the shared indicator was added intentionally to both advisories; as of the advisories, Cisco has not resolved that question.




