Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.
Related Posts:
OnePlus Session Takeover Vulnerability Exposes Android Data
NVIDIA Patches Triton Inference Server Vulnerabilities
Apache Artemis Vulnerabilities Demand Immediate Action
The post Cisco FMC Vulnerabilities Actively Exploited in the Wild appeared first on Daily CyberSecurity.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center (FMC) flaw, tracked as CVE-2026-20316 (CVSS score of 5.3), to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2026-20316 is a static credential vulnerability in the web interface of Cisco Secure Firewall Ma
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog.
CVE-2026-20316 is a static credential vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to authenticate using a built-in low-privileged account and access sensitive information stored on the affected system.
“A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.” reads the advisory. “A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.”
The flaw stems from the presence of hardcoded credentials for a low-privileged user account. Although the account provides limited access, it could be combined with other Cisco Secure FMC Software vulnerabilities to achieve privilege escalation. The attack surface is reduced if the FMC management interface is not exposed to the public internet.
Cisco released the following hot fixes to address this issue:
Cisco confirmed active exploitation of the vulnerability in July 2026 and strongly urges customers to upgrade to a fixed software release immediately.
“In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” states the advisory.
Administrators can check for exploitation by running cat /var/log/messages | grep license in expert mode. If the logs contain references to /var/tmp/license.tmp, the device may have been compromised. Cisco advises organizations that suspect exploitation to contact TAC for recovery assistance and immediately rotate all user credentials, cryptographic keys, and certificates, as the vulnerability has been actively exploited.