Cisco patches exploited Firewall Management Center flaw that grants built-in account access
Cisco has patched a flaw in Secure Firewall Management Center that attackers were already exploiting to log into devices. Tracked as CVE-2026-20316, it stems from static credentials for a low-privilege account built into the software, letting an unauthenticated remote attacker sign in and read sensitive data. Cisco scored it 5.3 but rated it High because the access can be chained with other flaws to escalate privileges. In the same cycle it patched CVE-2026-20079, a separate critical authentication bypass that reaches root, and shipped one set of hot fixes with a shared indicator suggesting the two could be combined. There are no workarounds.
- Check
- Upgrade Secure FMC to a fixed release now, and check for compromise by searching device logs for references to /var/tmp/license.tmp, which Cisco lists as an indicator.
- Affected
- Organizations running Cisco Secure Firewall Management Center releases 7.0, 7.2, 7.4, 7.6, 7.7, or 10.0 (CVE-2026-20316); the flaw is exploited, and chaining with the root-level bypass raises the stakes.
- Fix
- Apply Cisco's hot fixes, since there is no workaround, keep the FMC management interface off the public internet, and if the indicator appears, rotate all device credentials, keys, and certificates.