CVE-2026-20316 is an actively exploited Cisco FMC vulnerability involving static credentials. Patch affected systems immediately to prevent unauthorized access.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| secure_firewall_management_center | 7.0.0 | 7.0.9 | vulnerable |
| secure_firewall_management_center | 7.2.0 | 7.2.11 | vulnerable |
| secure_firewall_management_center | 7.3.0 | 7.3.1.2 | vulnerable |
| secure_firewall_management_center | 7.4.0 | 7.4.7 | vulnerable |
| secure_firewall_management_center | 7.6.0 | 7.6.5 | vulnerable |
| secure_firewall_management_center | 7.7.0 | 7.7.12 | vulnerable |
| secure_firewall_management_center | 10.0.0 | 10.0.1 | vulnerable |
Cisco has released software updates to address this vulnerability by removing the static credentials. Consult the Cisco Security Advisory (cisco-sa-fmc-static-cred-BET3Cjh) for specific patch availability for your release train and apply them immediately.
Immediately upgrade Cisco FMC software if running vulnerable versions including 7.0.x (up to 7.0.9), 7.2.x (up to 7.2.11), 7.3.x, 7.4.x, 7.6.x, 7.7.x, or 10.0.x. Ensure systems are moved to a fixed release version as specified in Cisco's technical documentation.
Limit access to the FMC management interface to trusted internal networks only. Use VPNs, access control lists (ACLs), or jump servers to ensure the web interface is not reachable from the public internet, which significantly reduces the attack surface.
Review web server logs and audit trails for successful logins from unexpected IP addresses using low-privileged accounts. Watch for subsequent suspicious activity that might indicate an attempt to elevate privileges or exfiltrate sensitive configuration data.
"Monitor Cisco FMC audit logs for successful logins to the web management interface from unexpected or external IP addresses, particularly those associated with low-privileged accounts. Use network security monitoring to identify unauthorized HTTPS traffic to the FMC. Since this vulnerability is often chained, look for subsequent indicators of privilege escalation or unusual configuration changes. Review CISA’s 'Forensics Triage Requirements' for specific guidance on identifying compromise in Cisco environments."
Experience superior visibility and a simpler approach to cyber risk management