Cisco FMC flaw added to CISA’s exploit list—patch now

Cisco Secure Firewall Management Center (FMC) customers face a new urgency to patch after U.S. cybersecurity authorities flagged a static credential vulnerability as actively exploited in the wild. The flaw, tracked as CVE-2026-20316 (CVSS 5.3), allows unauthenticated remote attackers to log in using a hardcoded low-privileged account and access sensitive data on vulnerable systems. CISA added the issue to its Known Exploited Vulnerabilities (KEV) catalog on July 29, 2026, prompting federal agencies to remediate the flaw by August 1 under Binding Operational Directive 22-01.
The weak link in enterprise defenses
The vulnerability stems from hardcoded credentials for a low-privileged user account in Cisco FMC Software’s web interface. While the account grants limited access, attackers could chain it with other flaws to escalate privileges. Cisco’s advisory notes that exploitation has been observed since July 2026, with threat actors leveraging the flaw to siphon sensitive information from affected systems. The company has released hot fixes for versions 7.0 through 10.0, each tailored to a specific release train. Administrators can check for signs of compromise by searching /var/log/messages for references to /var/tmp/license.tmp in expert mode, a potential indicator of exploitation.
Cisco urges immediate upgrades and advises organizations that suspect compromise to rotate all user credentials, cryptographic keys, and certificates, then contact Cisco TAC for recovery support. The company also recommends isolating the FMC management interface from public internet exposure to shrink the attack surface.
Why it matters
This is not just another advisory—it’s a concrete deadline for federal agencies and a reminder for private firms to prioritize known exploited flaws. The KEV catalog now pressures organizations to treat CVE-2026-20316 as an active threat, not a theoretical risk. For defenders, the episode underscores the importance of timely patching and credential hygiene, especially when hardcoded accounts are involved. With active exploitation confirmed, delays in applying hot fixes could expose networks to data theft or further lateral movement.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

