CVE-2026-20316: Cisco Secure FMC Skeleton Key Exploited as a Zero-Day

Red | Vulnerability
Download PDF
TA2026218 | CVE-2026-20316: Cisco Secure FMC Skeleton Key Exploited as a Zero-Day
HIVE PRO

Threat Advisory • Vulnerability Report • Admiralty Code A1

CVE-2026-20316: Cisco Secure FMC Skeleton Key Exploited as a Zero-Day

Cisco has disclosed CVE-2026-20316, an actively exploited zero-day in Cisco Secure Firewall Management Center (FMC) Software rooted in hard-coded, low-privilege credentials that let unauthenticated remote attackers log in without stealing or guessing anything.

TA Number: TA2026218 Date of Publication: July 31, 2026 Admiralty Code: A1 First Seen: July 2026 Affected Products: Cisco Secure Firewall Management Center Software
CVE-2026-20316 Actively Exploited Zero-Day Hard-Coded Credentials Hot Fix Available
CVE IDCVE-2026-20316
NameCisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Affected ProductCisco Secure Firewall Management Center (FMC) Software
Zero-DayYes
CISA KEVYes
PatchAvailable

Hard-Coded Credentials in Cisco Secure FMC Enable Remote Exploitation

Cisco has disclosed CVE-2026-20316, an actively exploited zero-day flaw in the web interface of Cisco Secure Firewall Management Center (FMC) Software. The root of the problem is a set of static, built-in credentials for a low-privilege account that ships with the software. Because those credentials are hard-coded, an unauthenticated, remote attacker can log in to an exposed device and read sensitive data as that low-privilege user, without needing to steal or guess anything. Cisco's PSIRT became aware of active exploitation of CVE-2026-20316 in July 2026. Because the flaw is already being actively exploited, prompt patching of affected Cisco Secure Firewall Management Center Software is necessary.

CVENameAffected ProductZero-DayCISA KEVPatch
CVE-2026-20316Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityCisco Secure Firewall Management Center (FMC) SoftwareYESYESYES

How CVE-2026-20316 Exposes Cisco Secure FMC to Unauthenticated Access

1

Static, hard-coded low-privilege account

Cisco has addressed CVE-2026-20316, a vulnerability in Cisco Secure Firewall Management Center (FMC) Software that is actively exploited. The weakness lives in the web interface of Cisco Secure Firewall Management Center Software and exists regardless of how the device is configured. The software ships with static user credentials tied to a low-privilege account, and because those credentials are fixed rather than unique per deployment, anyone who knows them can authenticate.

2

Straightforward, unauthenticated exploitation

The exploitation mechanism for CVE-2026-20316 is straightforward, which is part of what makes it dangerous. An unauthenticated, remote attacker uses the built-in account to log in to the Cisco Secure FMC web interface over the network. No prior access, phishing, or additional exploit is required for the initial login. Once authenticated, the attacker can access sensitive data within the affected system as the low-privileged user. Cisco has noted that the attack surface is meaningfully reduced when the FMC management interface is not reachable from the public internet, so internet-exposed management interfaces carry the highest risk.

3

Affected releases and confirmed scope

The affected scope spans multiple Cisco Secure FMC Software releases, including builds across the 7.0, 7.2, 7.3, 7.4, 7.6, 7.7, and 10.0 trains before the fixed hot-fix versions. Cisco has confirmed that Cloud-Delivered FMC (cdFMC), Firewall Device Manager (FDM), Secure Firewall ASA Software, Secure Firewall Threat Defense (FTD) Software, and Security Cloud Control (SCC) are not affected by CVE-2026-20316. Active exploitation is confirmed. Organizations running affected Cisco Secure FMC Software should upgrade to the latest fixed hot-fix releases without delay.

CVE IDAffected ProductsAffected CPECWE ID
CVE-2026-20316Cisco Secure Firewall Management Center (FMC) Software (7.0.x through 7.7.x and 10.0.x releases prior to the fixed hot-fix builds)cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*CWE-259

Patching and Hardening Against CVE-2026-20316

1

Apply the Cisco hot fix immediately

Cisco has released hot fixes for every affected train — 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 — available from the Software Center on Cisco.com. There are no workarounds for CVE-2026-20316, so upgrading to the fixed hot-fix build is the only real remediation. Given confirmed active exploitation and the federal August 1, 2026 deadline, treat patching of Cisco Secure FMC Software as urgent.

2

Check for signs of exploitation

In expert mode, run cat /var/log/messages | grep license on the FMC device. If the output references /var/tmp/license.tmp, the vulnerability may have been exploited. If you see this indicator or otherwise suspect compromise, contact the Cisco Technical Assistance Center (TAC) for recovery guidance.

3

Rotate credentials and keys

Because exploitation of CVE-2026-20316 has been ongoing, Cisco recommends rotating all user credentials, keys, and certificates on any affected Cisco Secure FMC device, even after patching, to ensure an attacker who already logged in cannot retain access.

4

Restrict management interface exposure

Ensure the FMC management interface is not reachable from the public internet. Placing it behind a VPN or restricting it to a trusted management network sharply reduces the attack surface for CVE-2026-20316 and similar flaws, and should be standard practice for security appliance consoles.


Potential MITRE ATT&CK TTPs

T1078 / T1078.001
Initial Access
Valid Accounts — Default Accounts
T1005
Collection
Data from Local System
T1068
Privilege Escalation
Exploitation for Privilege Escalation
T1588 / T1588.006
Resource Development
Obtain Capabilities — Vulnerabilities

Patch Link and References

Cisco's advisory for CVE-2026-20316 details the affected Cisco Secure Firewall Management Center Software releases and the hot fixes available for each train.

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.