Cisco is warning customers that a vulnerability in its Secure Firewall Management Center (FMC) software, caused by static credentials built into a low-privilege account, was actively exploited in zero-day attacks before a fix was available.
Hard-Coded Credentials in a Low-Privilege Account
The flaw, tracked as CVE-2026-20316, stems from static credentials embedded in a low-privilege account within Cisco Secure FMC Software, the centralized platform organizations use to manage and monitor their Cisco firewall deployments. An unauthenticated remote attacker who knows or discovers those credentials can log in to an affected device using that account, gaining a foothold on infrastructure that is meant to be tightly restricted. Cisco says the attack surface is reduced when the FMC management interface is not exposed directly to the public internet, though the company has not disclosed how many organizations had internet-facing management interfaces at the time of exploitation.
Cisco Learned of Active Exploitation in July, Disclosed in September
Cisco said it became aware of active exploitation of the flaw in July 2026 but has not shared when the attacks actually began, who is behind them, or which organizations were targeted. The vulnerability was reported by Jimi Sebree of Horizon3.ai. Cisco has released hot fixes addressing CVE-2026-20316, alongside a related flaw tracked as CVE-2026-20079 that the company says can achieve root access on affected devices without relying on the static credentials at all. No workarounds fully address either vulnerability short of applying the fixed software, and Cisco is urging FMC administrators to patch immediately and review whether their management interfaces are unnecessarily exposed to the internet.

Leave a Reply