Overview
- Cisco confirmed late Wednesday that CVE‑2026‑20316 is being actively exploited in zero‑day attacks to log in to Secure Firewall Management Center (FMC) devices using a built‑in low‑privilege account.
- The flaw stems from static credentials for a low‑privilege account baked into FMC software that let an attacker authenticate without prior access to the device.
- Cisco released hotfixes for FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 and said there are no full workarounds, urging administrators to install fixes and rotate credentials if compromise is suspected.
- Cisco published an indicator of compromise for detection—search /var/log/messages for entries referencing /var/tmp/license.tmp—and advised customers to contact Cisco TAC for recovery help if the IOC appears.
- The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities list, accelerating remediation deadlines for federal agencies because the access can be chained with other FMC bugs to gain greater control.