DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // cisco-sa-fmc-static-cred-BET3Cjh // PUBLISHED 2026-07-29

Cisco Secure FMC Hard-Coded Password — Zero-Day Under Active Exploitation, Chains with CVSS 10.0 Auth Bypass (CVE-2026-20316 + CVE-2026-20079)

CVE-2026-20316 is an actively exploited use of hard-coded credentials in Cisco Secure Firewall Management Center (FMC) that allows an unauthenticated remote attacker to log in via a low-privileged account and access sensitive data. CISA added it to the KEV on July 29, 2026 with a federal patch deadline of August 1, 2026. In tandem, Cisco updated its advisory for the CVSS 10.0 authentication bypass CVE-2026-20079 — which enables arbitrary script execution with root access — to include shared indicators of compromise, suggesting threat actors may be chaining both flaws for full FMC compromise.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Cisco Secure Firewall Management Center (FMC) Software 6.4.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.0.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.1.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.2.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.3.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.4.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.6.x
MEDIUM
LIMITED
PATCHED
Cisco Secure Firewall Management Center (FMC) Software 7.7.x
MEDIUM
LIMITED
PATCHED

Apply available Cisco hot fixes immediately per the cisco-sa-fmc-static-cred-BET3Cjh advisory. Use the Cisco Software Checker to identify your correct remediation path. Restrict FMC management interface access to trusted internal networks only — do not expose to the public internet. No configuration-based workaround exists; patching is mandatory. Conduct forensic triage for /var/tmp/license.tmp IOC presence.

Search for the presence of /var/tmp/license.tmp on FMC hosts as a key indicator of compromise. Monitor FMC authentication logs for logins from unexpected low-privileged accounts. Alert on any HTTP requests to the FMC web interface from external IP ranges. Correlate with Cisco-provided Snort signatures for CVE-2026-20316 exploitation attempts.

EXPORT FORMATTED IOC PACKAGE
Splunk SPL · KQL · Sigma rules · Firewall blocklists — subscriber feature
SUBSCRIBE →
#
TYPE
INDICATOR
CONTEXT
FIRST SEEN
001
HASH
/var/tmp/license.tmp (file presence on FMC host)
Compromise Indicator File
2026-07-29
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
  • https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-20316
  • https://nvd.nist.gov/vuln/detail/CVE-2026-20079
SHARE BRIEF:✕ Post on Xin Share on LinkedIn