Static account in Cisco Secure FMC actively exploited
On 29 July 2026 CISA added CVE-2026-20316 to its catalog of known exploited vulnerabilities, citing evidence of active exploitation. The vulnerability sits in the web interface of Cisco Secure Firewall Management Center, and is caused by a static user account shipped with the software. Cisco states that its PSIRT became aware of active exploitation in July 2026, and that no workaround exists. Cisco has assigned the advisory a Security Impact Rating of High, even though the CVSS score is 5.3. CISA set 1 August 2026 as the due date for United States federal agencies.
What happens technically
Cisco Secure Firewall Management Center, formerly known as Firepower Management Center, is the console that manages Cisco firewalls. The weakness is classified as CWE-259, use of hard-coded password, and Cisco describes it as static user credentials for a low privileged account. According to the advisory an unauthenticated attacker can log in to an affected system over the network, and read data available to that low privileged account. The vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yields 5.3 points, and expresses that the attack happens over the network, without privileges and without user interaction, with limited loss of confidentiality. Cisco has nevertheless set its own severity to High rather than Medium, stating explicitly that the vulnerability can be used together with other vulnerabilities in the same product to elevate privileges. The vulnerability was reported by Jimi Sebree of Horizon3.ai, and carries the Cisco bug identifier CSCwt95997.
The vulnerability affects Cisco Secure FMC regardless of how the device is configured, according to the advisory. Cisco has confirmed that cloud delivered cdFMC, Firewall Device Manager, the ASA software, the Threat Defense software and Security Cloud Control are not affected. There is no workaround, and the fix arrives as hot fixes for the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 release lines. Cisco also names a trace to look for: in the /var/log/messages log, a line showing that package information was read from /var/tmp/license.tmp may mean the vulnerability was exploited on that device. Where exploitation is suspected, Cisco asks customers to contact its technical assistance centre, and recommends as a minimum rotating all user credentials, keys and certificates on the device, because exploitation has been ongoing. The sources differ on severity: Cisco records limited loss of confidentiality in the CVSS vector, while CISA in its SSVC entry assesses exploitation as active and automatable and the technical impact as total. Cisco notes that the attack surface is reduced when the management interface has no public internet access.
What this means for you if you run Cisco Secure FMC
The console you manage your firewalls from is not an incidental application in your portfolio. It holds the rule sets, the network topology and the event logs of the very systems meant to protect the organisation. An unauthenticated login granting read access to that console therefore weighs more heavily than the number 5.3 suggests. Our assessment is that Cisco's own reasoning is the most important sentence in the entire advisory. The account is a foothold that can be combined with other weaknesses in the same product. When CISA also judges the exploitation to be automatable, you should expect large scale scanning against exposed management interfaces.
Two questions are more urgent than the rest. The first is whether your management interface is reachable from the outside at all. Cisco ties the reduced attack surface precisely to the absence of public internet access. The second is whether your device may already have been exploited, since Cisco writes that exploitation has been ongoing. The 1 August 2026 due date applies to United States federal agencies and not to you, but the date still states plainly how fast CISA believes this has to be handled. If your organisation is covered by NIS2, you have to demonstrate that known exploited vulnerabilities in security equipment are handled against a fixed deadline, and that the question of compromise is answered before the device is declared clean. Install the hot fix without checking the log and you close the hole, but you do not learn whether somebody was already inside.
Berigo recommends
- Install the Cisco hot fix for the release line you run, and confirm the installation on every single console. No workaround can replace the fix.
- Remove the management interface from the internet, and restrict access to a dedicated management network with strong authentication.
- Look for the trace Cisco names in /var/log/messages before declaring the device clean, and treat a finding as an incident rather than as a log line.
- Rotate user credentials, keys and certificates on the console wherever exploitation cannot be ruled out, as Cisco recommends.
- Set a fixed internal deadline for vulnerabilities listed in the CISA catalog of known exploited vulnerabilities, and follow the deadline up in your management system.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch