Affected Systems
Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control. All configurations vulnerable.
Exploitation Status
Active exploitation confirmed since July 2026. Attacker identity, timeline, and targeted organizations unknown. Vulnerability reported by Jimi Sebree of Horizon3.ai. Cisco indicates CVE-2026-20316 is being chained with other unspecified FMC vulnerabilities to escalate privileges.
Business Impact
Unauthenticated remote attackers can use hardcoded credentials to access low-privilege account and view sensitive data. Cisco warns this access is being combined with other FMC vulnerabilities (not disclosed) to achieve privilege escalation. CVSS 5.3 but rated High severity by vendor due to chaining potential. Risk reduced if FMC management interface is not internet-facing. Compromised devices require full credential rotation.
Urgency
🔴 Immediate
Recommended Actions
- Apply Cisco hot fixes immediately for Secure FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 (no workarounds available)
- Search /var/log/messages for IOC using command in expert mode: cat /var/log/messages | grep license — look for /var/tmp/license.tmp entries indicating compromise
- If IOC detected, rotate all user credentials, SSH keys, and certificates on affected FMC devices immediately
- Ensure FMC management interfaces are not exposed to the public internet to reduce attack surface
- Contact Cisco TAC for incident response assistance if compromise is suspected or confirmed
