CISA Flags Cisco FMC Zero-Day as Actively Exploited

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA added CVE-2026-20316, a static-credential vulnerability in Cisco Secure Firewall Management Center (FMC) Software with a CVSS of 5.3, to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation.
- Cisco traced the flaw to hardcoded credentials on a low-privileged account that let unauthenticated remote attackers log in and read sensitive data, and rated it Security Impact Rating "High" rather than Medium because it can chain with other FMC bugs to elevate privileges.
- Cisco confirmed active exploitation began earlier this month but disclosed no details on threat actors or methods; Jimi Sebree of Horizon3.ai was credited with discovering and reporting the vulnerability.
- Cisco released hot fixes spanning FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0, and told customers to run
cat /var/log/messages | grep license— a returned/var/tmp/license.tmppath may indicate compromise. - Cisco also refreshed its advisory for CVE-2026-20079 (CVSS 10.0, an authentication-bypass flaw enabling arbitrary script execution as root) with the same hot fixes and IoC; no malicious use of that bug has been seen, but the shared indicator hints attackers could chain the two for root code execution.
- Federal Civilian Executive Branch agencies are required to apply the fixes by August 1, 2026 under CISA's binding operational directive.
Why it matters: The 5.3 base score undersells the risk: Cisco itself raised the rating because this credential flaw chains with a separate CVSS 10.0 FMC authentication bypass (CVE-2026-20079) for root-level code execution. FCEB agencies face an August 1 deadline, and any organization running Cisco Secure FMC with a public-internet management interface should patch before the same chain is weaponized beyond the limited exploitation already observed.




