ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

criticalVulnerability exploited in the wildimportance 60CVE-2026-20316CVE-2026-20079CVE-2026-20131

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20131
Unauthenticated Java Deserialization RCE in Cisco FMC and SCC

CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization.

10.033% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC) Software version ranges not yet published in available data
  • Cisco Security Cloud Control (SCC) Firewall Management version ranges not yet published in available data
largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)
Full article519 words · extracted from helpnetsecurity.com · click to collapse

A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned.

Two FMC flaws, one indicator of compromise

CVE-2026-20316, reported by Jimi Sebree of Horizon3.ai, is found in the FMC software’s web interface. The static user credentials are for a low-privileged account, and they can be used by attackers to log in to an affected device and potentially access sensitive data.

Cisco noted that it could also be leveraged in conjunction with other vulnerabilities, potentially allowing attackers to gain elevated privileges and thus greater capacity for more in-depth compromise. (The company did not say such chaining was actually occurring.)

The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on Wednesday, ordering US civilian federal agencies to address the flaw by August 1, 2026, and to check whether the vulnerability has been exploited on their installations.

Cisco says its Product Security Incident Response Team became aware of active exploitation of this vulnerability this month, and has provided hotfixes.

It has also provided instructions on how to check for indicators of compromise (IoCs) in the system log – the presence of package_info.pl execution referencing /var/tmp/license.tmp indicates possible exploitation.

“If exploitation is suspected, contact the Cisco Technical Assistance Center (TAC) for assistance with recovery options. At a minimum, Cisco recommends that customers rotate all user credentials, keys, and certificates on the Cisco Secure FMC device because active exploitation of this vulnerability has been ongoing,” the company advised<. Cisco published the same IoC check in a separate advisory, updated the same day, for a related FMC flaw. That one is for CVE-2026-20079, which was disclosed in March 2026 after getting flagged by Cisco during internal security testing and, according to the updated advisory, it may allow unauthenticated attackers to “bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.”

However, the company says that its incident response team is not aware of any public announcements or malicious use of CVE-2026-20079.

Cisco FMC in attackers’ sights

Cisco’s networking and security devices and solutions are often compromised via known and zero-day vulnerabilities, but Cisco Secure Firewall Management Center had not become a popular target until recently.

In March 2026, Cisco disclosed two critical FMC vulnerabilities: the CVE-2026-20079 authentication bypass mentioned above, and CVE-2026-20131, a remote code execution flaw exploited by sending a crafted serialized Java object to a vulnerable device’s web-based management interface. Soon after, Amazon CISO CJ Moses revealed that the company’s honeypots had detected the Interlock ransomware gang exploiting the latter as a zero-day, beginning January 26, 2026.

FMC’s web-based management interface is the weak point attackers have been passing through.

“If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced,” Cisco noted in the advisories for all three FMC vulnerabilities.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/30/cisco-fmc-cve-2026-20316-exploited/