CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)

CISA has warned U.S. government agencies about an actively exploited vulnerability impacting Cisco Secure Firewall Management Center. CISA added the CVE-2026-20316 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 1, 2026. Successful exploitation of this vulnerability could allow an attacker to log in to the affected system and access sensitive data as a low-privileged user.

Cisco mentioned in their advisory that their PSIRT became aware of active exploitation of this vulnerability in July 2026.

Cisco Firewall Management Center analyzes network vulnerabilities, prioritizes attacks, and recommends protections to support security teams. FMC provides unified firewall management, application control, intrusion prevention, URL filtering, and malware defense. It also offers real-time visibility across networks to manage applications and malware outbreaks.

Vulnerability Details

The vulnerability in the web interface of Cisco Secure Firewall Management Center Software stems from the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. Successful exploitation of the vulnerability could allow the attacker to log in to the affected system and access sensitive data as a low-privileged user.

Cisco mentioned in the advisory that, “If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.”

Indicators of Compromise

To determine if this vulnerability may have been exploited, use the cat /var/log/messages | grep license CLI command in expert mode. If the log message in the output includes /var/tmp/license.tmp, this vulnerability may have been exploited on the Cisco Secure FMC device.

Affected Versions

The vulnerability affects the following Cisco Firepower Management (FMC) versions:

  • 7.0.0 prior to 7.0.9
  • 7.1.0 prior to 7.2.11
  • 7.3.0 prior to 7.4.4
  • 7.6.0 prior to 7.6.4
  • 7.7.0 prior to 7.7.11

Mitigation

Cisco has released software updates to address the vulnerability.

Customers can refer to the Cisco Security Advisory (cisco-sa-fmc-static-cred-BET3Cjh) for information about the vulnerability.

Qualys Detection

Qualys customers can scan their devices with QID 317862 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh