VULNERABILITY OVERVIEW
A hard-coded static password (CWE-259) embedded in the Cisco Secure FMC web interface allows an unauthenticated remote attacker to log in using a built-in low-privileged account and access sensitive configuration data, security policies, and event logs. Despite a CVSS of 5.3, Cisco assigned a High Security Impact Rating because the flaw chains with CVE-2026-20079 (CVSS 10.0) via a shared IOC (/var/tmp/license.tmp) to achieve full root-level compromise of the management plane. CISA added this to KEV on July 29, 2026 with a federal remediation deadline of August 1, 2026; Cisco confirmed active zero-day exploitation during July.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:L · I:N · A:N
AFFECTED VERSIONS
Cisco Secure FMC Software all versions prior to hotfix releasesCITATIONS
- → https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
- → https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20316/
- → https://cybersecuritynews.com/cisco-firewall-management-center-0-day/
- → https://socprime.com/blog/cve-2026-20316-cisco-fmc-zero-day-exploited/
- → https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh