CISA Warns of Zero-Day Exploitation in Cisco Secure Firewall Management Center
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has added a critical vulnerability in **Cisco Secure Firewall Management Center (FMC) Software** to its Known Exploited Vulnerabilities (**KEV**) catalog. Tracked as **CVE-2026-20316**, this zero-day flaw allows unauthenticated remote attackers to gain low-privilege access, potentially exposing sensitive data. Organizations are urged to apply hotfixes immediately.

The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** recently issued an alert, adding a newly disclosed security flaw impacting **Cisco Secure Firewall Management Center (FMC) Software** to its Known Exploited Vulnerabilities (**KEV**) catalog. This action follows confirmed reports of zero-day exploitation in the wild.
### The Vulnerability: CVE-2026-20316
The vulnerability, assigned **CVE-2026-20316** (CVSS score: 5.3), is a significant concern for network security. It allows an unauthenticated, remote attacker to log in to an affected device using a low-privilege account, thereby gaining access to sensitive data within susceptible systems.
**Cisco** confirmed the flaw in a security advisory, stating, "This vulnerability is due to the presence of static user credentials for a low-privileged account." A successful exploit could allow the attacker to log in and access sensitive data as the low-privileged user.
### Attack Surface and Impact
**Cisco** noted that the attack surface associated with **CVE-2026-20316** is reduced if the **FMC** management interface lacks public internet access. Despite its initial CVSS score, **Cisco** has assigned it a Security Impact Rating (SIR) of High. This elevated rating is due to the potential for chaining this vulnerability with other **Cisco Secure FMC Software** flaws to achieve privilege escalation.
Security researcher **Jimi Sebree** of **Horizon3.ai** is credited with discovering and reporting the flaw. While **Cisco** acknowledged active exploitation began earlier this month, specific details regarding the attackers or the precise methods of exploitation remain undisclosed.
### Patching and Mitigation
**Cisco** has released hotfix versions to address the issue across various **Cisco Secure FMC Software** releases:
* 7.0 - `Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar`
* 7.2 - `Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar`
* 7.4 - `Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar`
* 7.6 - `Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar`
* 7.7 - `Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar`
* 10.0 - `Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar`
### Indicators of Compromise (IoCs)
As an immediate measure, **Cisco** advises customers to use the `cat /var/log/messages | grep license` CLI command in expert mode. If the output includes `/var/tmp/license.tmp`, it suggests potential exploitation on the **Cisco Secure FMC** device:
### Chaining with CVE-2026-20079
In related news, **Cisco** has updated its advisory for **CVE-2026-20079** (CVSS score: 10.0), a critical authentication bypass flaw also affecting **Cisco Secure FMC Software**. The update includes a second bug ID (**CSCwt95974**) and the same indicators of compromise and hotfixes as **CVE-2026-20316**.
While **Cisco** is not aware of malicious exploitation for **CVE-2026-20079** itself, the shared `/var/tmp/license.tmp` indicator raises concerns. Given that **CVE-2026-20079** can lead to arbitrary executable script file execution and root access, threat actors could potentially chain these two flaws for comprehensive code execution.
### Urgent Action Required
Due to the active exploitation of **CVE-2026-20316**, Federal Civilian Executive Branch (**FCEB**) agencies are strongly recommended to apply the necessary fixes by August 1, 2026. All other organizations using **Cisco Secure FMC Software** should prioritize these updates to protect their networks from potential compromise.