ADVISORY SUMMARY
CVE-2026-20316 is an actively exploited use of hard-coded credentials in Cisco Secure Firewall Management Center (FMC) that allows an unauthenticated remote attacker to log in via a low-privileged account and access sensitive data. CISA added it to the KEV on July 29, 2026 with a federal patch deadline of August 1, 2026. In tandem, Cisco updated its advisory for the CVSS 10.0 authentication bypass CVE-2026-20079 — which enables arbitrary script execution with root access — to include shared indicators of compromise, suggesting threat actors may be chaining both flaws for full FMC compromise.
AFFECTED SYSTEMS
MITIGATION GUIDANCE
Apply available Cisco hot fixes immediately per the cisco-sa-fmc-static-cred-BET3Cjh advisory. Use the Cisco Software Checker to identify your correct remediation path. Restrict FMC management interface access to trusted internal networks only — do not expose to the public internet. No configuration-based workaround exists; patching is mandatory. Conduct forensic triage for /var/tmp/license.tmp IOC presence.
DETECTION SIGNATURES
Search for the presence of /var/tmp/license.tmp on FMC hosts as a key indicator of compromise. Monitor FMC authentication logs for logins from unexpected low-privileged accounts. Alert on any HTTP requests to the FMC web interface from external IP ranges. Correlate with Cisco-provided Snort signatures for CVE-2026-20316 exploitation attempts.
INDICATORS OF COMPROMISE
REFERENCES
- → https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- → https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
- → https://nvd.nist.gov/vuln/detail/CVE-2026-20316
- → https://nvd.nist.gov/vuln/detail/CVE-2026-20079