Cisco FMC Zero-Day Under Active Attack, CISA Orders Patch by 2026

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on Wednesday, confirming active exploitation of the Cisco Secure FMC flaw.
- Cisco disclosed that the vulnerability stems from static credentials for a low-privileged account, enabling unauthenticated remote access to sensitive data on exposed systems.
- Cisco assigned a High Security Impact Rating due to the risk of chaining this flaw with others, such as CVE-2026-20079, to achieve root-level code execution.
- Jimi Sebree of Horizon3.ai discovered and reported the vulnerability, which Cisco confirmed was actively exploited earlier in July 2026.
- Cisco released hot fixes for affected versions 7.0 through 10.0 of Secure FMC Software and provided specific IoCs involving '/var/tmp/license.tmp' for detection.
- Federal Civilian Executive Branch agencies are required to apply patches by August 1, 2026, under CISA's binding operational directive.
Why it matters: The mandatory August 2026 deadline for federal agencies to patch creates urgency, as unpatched systems risk data exposure and potential privilege escalation through exploit chaining. The presence of active attacks and shared indicators with a critical authentication bypass raises the real-world impact beyond theoretical risk.




