Cyber Security News

Cisco Firewall Management Center 0-Day Actively Exploited to Access Sensitive Data

Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This vulnerability, tracked as CVE-2026-20316, arises from static credentials embedded in the FMC web interface.

Although the flaw carries a CVSS score of 5.3, Cisco assigned it a High Security Impact Rating because attackers may combine it with other vulnerabilities to gain elevated privileges. The issue falls under CWE-259, which pertains to the use of hard-coded or static passwords.

An unauthenticated remote attacker can exploit CVE-2026-20316 by logging in to an affected FMC appliance using the exposed low-privilege account. Successful exploitation allows the attacker to access sensitive data associated with that account.

Cisco noted that the exposure of the management interface affects the overall risk. FMC systems without public internet access have a reduced attack surface however, internal attackers or compromised systems could still target them.

The Cisco Product Security Incident Response Team (PSIRT) became aware of active exploitation in July 2026. The company urges customers to apply the available hotfixes immediately, as there is no workaround for this vulnerability.

This issue affects Cisco Secure FMC Software regardless of the device configuration. Cisco confirmed that Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, and Security Cloud Control are not affected.

Administrators can check FMC logs for signs of possible exploitation. Cisco recommends running the following command in expert mode:

cat /var/log/messages | grep license

A log entry referencing /var/tmp/license.tmp may indicate that the vulnerability has been exploited. Cisco provided an example showing the www account executing the package_info.pl utility with this temporary file as an argument.

Organizations that detect suspicious activity should contact the Cisco Technical Assistance Center for recovery support. Cisco also recommends rotating all user credentials, cryptographic keys, and certificates stored on the affected FMC appliance since exploitation has been ongoing.

Cisco has released hotfixes for FMC Software versions 7.0, 7.2, 7.4, 7.6,7.7, and 10.0. Administrators should obtain the appropriate update from the Cisco Software Center and follow the Firepower Hot Fix Release Notes during deployment.

Security teams should restrict access to FMC management interfaces, eliminate direct exposure to the public internet, monitor authentication and system logs, and review the platform for unusual administrative activity. Applying Cisco’s fixed software is the only complete remediation for CVE-2026-20316.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago