Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html

ONE SENTENCE SUMMARY:

CISA added a Cisco Secure FMC static-credential flaw to KEV amid zero-day abuse, urging hotfixes, IoC checks, and rapid patching.

MAIN POINTS:

  1. CISA listed CVE-2026-20316 in KEV after reports of in-the-wild zero-day exploitation.
  2. Vulnerability enables unauthenticated remote login using a built-in low-privilege account.
  3. Root cause involves static user credentials embedded for a low-privileged FMC account.
  4. Exploitation allows access to sensitive data available to that low-privileged user.
  5. Exposure is reduced when the FMC management interface lacks public internet accessibility.
  6. Cisco raised severity to SIR High because it can chain with other vulnerabilities.
  7. Researcher Jimi Sebree (Horizon3.ai) discovered and reported the credential issue.
  8. Cisco confirmed active exploitation but withheld attacker details, timelines, and techniques.
  9. Hotfixes were released for FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.
  10. Cisco provided an IoC using logs showing /var/tmp/license.tmp referenced by package_info.pl.

TAKEAWAYS:

  1. Prioritize patching FMC systems immediately because KEV inclusion signals proven exploitation.
  2. Remove public exposure of the FMC management interface to meaningfully shrink attack surface.
  3. Hunt for compromise by grepping /var/log/messages for license and /var/tmp/license.tmp.
  4. Consider chaining risk with CVE-2026-20079, which can enable root-level code execution.
  5. Meet FCEB remediation timelines by applying Cisco hotfixes no later than August 1, 2026.