# Cisco warns of FMC static credential flaw exploited in zero-day attacks

_Wednesday, July 29, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Cisco warns of FMC static credential flaw exploited in zero-day attacks — Primary](https://www.bleepstatic.com/content/hl-images/2025/03/04/Cisco-headpic.jpg)

Cisco warned Tuesday that a high-severity static credential vulnerability in its Secure Firewall Management Center software was actively exploited in zero-day attacks.

The company said the flaw, tracked as CVE-2026-20316, allows an unauthenticated remote attacker to use built-in low-privilege credentials to log in and access sensitive data. Cisco assigned a High severity rating despite a CVSS score of 5.3 because the access can be combined with other vulnerabilities to elevate privileges, though it has not identified those additional flaws.

The vulnerability affects Secure FMC Software releases 7.0 through 10.0 regardless of configuration but does not impact Cloud-Delivered FMC or several other Cisco products. Cisco released hot fixes for all affected versions and said there are no workarounds. The company said it became aware of active exploitation in July 2026 but has not disclosed when attacks began, who is responsible, or which organizations were targeted.

Jimi Sebree of Horizon3.ai reported the vulnerability. Cisco also updated an advisory for a separate critical authentication bypass flaw, CVE-2026-20079, which carries a maximum CVSS score of 10.0. Cisco said it is not aware of malicious exploitation of that vulnerability. Both advisories share an indicator of compromise involving a log entry for /var/tmp/license.tmp, though Cisco has not explained whether the flaws are connected.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/)

---
Canonical: https://techandbusiness.org/newswire/k8UOl3NIYeE19BYW8RM0kn
Retrieved: 2026-07-30T05:55:32.935Z
Publisher: Tech & Business (techandbusiness.org)
