CISA Adds Cisco FMC CVE-2026-20316 to KEV
CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.
CISA added CVE-2026-20316 in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog on July 29, 2026, after confirming active exploitation. Cisco released hotfixes for several product branches and said there are no alternative mitigations for the flaw.
CISA added CVE-2026-20316 in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog on July 29, 2026, after confirming active exploitation. The U.S. agency also set an Aug. 1, 2026 remediation deadline for affected government organizations, according to information reported by SecurityWeek and other technical outlets.
What Cisco fixed
Cisco published a security advisory the same day for a static credential flaw in Cisco Secure Firewall Management Center, which it describes as a "static credential" issue. The company said there are no workarounds to mitigate CVE-2026-20316 and that the fix is to apply the software updates and hotfixes already available.
The vendor released specific patches for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. MyTech-Blog also says Cisco published hotfixes for several Cisco Secure FMC branches, including 7.0, 7.2, 7.4, 7.6 and 7.7, in line with the official advisory.
Active exploitation and technical scope
SecurityWeek reported that Cisco announced patches for the vulnerability while it was already being exploited actively as a zero-day. The Hacker News also said Cisco confirmed active exploitation in early July 2026, without giving an exact date or naming any actors.
The technical description is consistent across the sources reviewed. Tenable lists it as a low-privilege static-credential vulnerability that allows unauthenticated access to the FMC web interface. Cisco, according to the technical summary cited by MyTech-Blog, says the impact on confidentiality is low and that the flaw alone does not enable configuration changes or code execution. Even so, f4n6.co.uk notes that Cisco rates it internally with a Security Impact Rating of High, because those credentials can be combined with other known FMC vulnerabilities to escalate privileges.
Indicators and response context
The Hacker News said Cisco provided a specific diagnostic command, cat /var/log/messages | grep license, and that the presence of the /var/tmp/license.tmp path can be treated as a possible indicator of exploitation on an FMC device. Cisco also credits the initial report to researcher Jimi Sebree of Horizon3.ai.
CISA, for its part, posted on X that CVE-2026-20316, described as a case of "use of hard-coded password" in Cisco Secure Firewall Management Center, had been added to the KEV and urged users to apply available mitigations. WindowsForum linked the inclusion to Binding Operational Directive 26-04, which requires prioritizing remediation of high-risk KEV vulnerabilities on publicly exposed assets.
f4n6.co.uk expands the affected scope using NVD CPE data and mentions branches such as FMC 7.0.0 through 7.0.9, 7.2.0 through 7.2.11, 7.3.0 through 7.3.1.2 and 7.4.0 through 7.4.7. The Hacker News and BleepingComputer, cited by other coverage, agree that the flaw was used in zero-day attacks to gain unauthorized access to FMC devices.
Sources
- CVE-2026-20316tenable.com· Tenable
- Cisco Secure Firewall Management Center Software Static Credential Vulnerability (CVE-2026-20316)cisco.com· Cisco
- Cisco Secure FMC Zero-Day Exploited in the Wildsecurityweek.com· SecurityWeek
- Cisco FMC 脆弱性 2 件が KEV 登録|期限 3 日と対処手順mytech-blog.com· MyTech-Blog
- CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-Coded Password Vulnerabilityf4n6.co.uk· f4n6.co.uk
- CVE-2026-20316: CISA KEV Flags Cisco FMC Password Flawwindowsforum.com· WindowsForum
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Datathehackernews.com· The Hacker News
- Latest CVE-2026-20316 newsbleepingcomputer.com· BleepingComputer
- CISACyber post announcing KEV addition of CVE-2026-20316x.com· CISA



