Cisco FMC Critical Flaw CVE-2026-20316 Actively Exploited via Static Credentials
Cisco has warned that a critical vulnerability in its Firewall Management Center (FMC), tracked as CVE-2026-20316, is being actively exploited in zero-day attacks as of July 29, 2026. Attackers are leveraging hardcoded static credentials tied to a built-in low-privilege account to gain initial access to exposed FMC management interfaces. This foothold is then chained with a separate FMC vulnerability to escalate privileges to root, enabling theft of management credentials, keys, certificates, and configuration data. A forensic indicator of compromise is the execution of package_info.pl /var/tmp/license.tmp by the web process running as root, visible in system logs. Cisco urges affected users on versions 7.0 through 7.7 and 10.0 to apply available hotfixes immediately and restrict management plane access to trusted networks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in