Cisco FMC Zero-Day Added to CISA KEV Catalog

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA added CVE-2026-20316, a Cisco Secure Firewall Management Center flaw with a CVSS score of 5.3, to its Known Exploited Vulnerabilities catalog on Wednesday following reports of active zero-day exploitation.
- Cisco traced the vulnerability to static user credentials for a low-privileged account, which let unauthenticated remote attackers log in and access sensitive data, and rated it "High" rather than "Medium" because it can chain with other FMC vulnerabilities to elevate privileges.
- Horizon3.ai researcher Jimi Sebree discovered and reported the flaw; Cisco confirmed active exploitation began earlier this month but withheld details on attackers, timing, and methods.
- Cisco released hot fixes for FMC versions 7.0 through 10.0 and provided an indicator of compromise — running "cat /var/log/messages | grep license" and flagging "/var/tmp/license.tmp" as a possible exploitation marker.
- Cisco also updated its advisory for CVE-2026-20079 (CVSS 10.0), a separate critical authentication bypass in the same FMC product, adding the same IoC and hot fixes and indicating the two flaws could be chained for code execution.
- Federal Civilian Executive Branch agencies face an August 1, 2026 deadline to apply the fixes.
Why it matters: The chaining potential between CVE-2026-20316 and the critical CVE-2026-20079 (CVSS 10.0) turns a 5.3-rated flaw into a possible root-level code execution path — which is why Cisco upgraded its severity rating despite the low base score. Active exploitation, undisclosed attackers, and an August 1, 2026 FCEB patching deadline mean defenders should audit for the /var/tmp/license.tmp indicator immediately.




