Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What ‘mAh’ means for your phone’s battery, and why I focus on another metric instead

    July 29, 2026

    Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

    July 29, 2026

    ARK Analyst Says Crypto Entering Biggest Consolidation Phase

    July 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What ‘mAh’ means for your phone’s battery, and why I focus on another metric instead
    • Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
    • ARK Analyst Says Crypto Entering Biggest Consolidation Phase
    • Can’t sleep in the heat? These 8 tricks could save your night
    • Proposed mine expansion raising pollution concerns in Canada and US
    • A $20K campaign won a Nebraska Senate primary. Then the candidate quit. • OpenSecrets
    • Protests in Libya, Tunisia Amid Extreme Heat Wave
    • Salman Rushdie attacker convicted of terror offenses
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, July 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco warns of FMC static credential flaw exploited in zero-day attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 29, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.

    The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software.

    Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account.

    image

    While CVE-2026-20316 has a CVSS score of 5.3, Cisco assigned it a High severity rating because the access can be combined with other FMC vulnerabilities to elevate privileges.

    However, the company has not identified the additional vulnerabilities or explained how they are being used in attacks.

    The flaw affects Cisco Secure FMC Software regardless of device configuration, but does not impact Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software, or Security Cloud Control.

    Cisco has released hot fixes for Secure FMC releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. There are no workarounds that address the vulnerability, and customers are strongly advised to install the available fixes.

    Cisco says it became aware of active exploitation in July 2026 but has not shared when the attacks began, who is behind them, or what organizations were targeted. Jimi Sebree of Horizon3.ai reported the vulnerability.

    The company notes that the attack surface is reduced when the FMC management interface is not exposed to the public internet.

    To detect whether a Cisco FMC installation was compromised, administrators should review the /var/log/messages log file for signs that the vulnerability may have been exploited.

    Administrators can search for suspicious activity by running the following command in expert mode:

    
    cat /var/log/messages | grep license

    Cisco says a log entry containing /var/tmp/license.tmp, as shown below, may indicate that an FMC device was compromised:

    
    Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm

    The log entry shows the FMC web process, running under the www account, invoking Cisco’s package_info.pl script as root and supplying the /var/tmp/license.tmp file.

    If a device contains this IOC, admins should rotate all user credentials, keys, and certificates on the affected FMC device because exploitation has been ongoing.

    Organizations that believe they are compromised should also contact the Cisco TAC for assistance with recovery.

    Critical FMC authentication bypass flaw also patched

    Cisco also updated an advisory for a separate critical FMC authentication bypass vulnerability tracked as CVE-2026-20079, which has a maximum CVSS score of 10.0.

    The flaw allows an unauthenticated, remote attacker to bypass authentication and execute scripts and commands as root by sending specially crafted HTTP requests to an affected FMC device.

    Cisco says the vulnerability is caused by an improper system process created when the system boots.

    Unlike CVE-2026-20316, CVE-2026-20079 does not require credentials or prior access to the device.

    Cisco originally disclosed CVE-2026-20079 in March 2026 and updated the advisory on July 29 to add a second bug ID, hot fixes, and indicators of compromise.

    However, Cisco says it is not aware of malicious exploitation of this vulnerability.

    The company published the same /var/tmp/license.tmp indicator in both advisories, but has not explained whether the vulnerabilities are connected.

    Furthermore, Cisco’s description of CVE-2026-20079 indicates that it can be exploited without using the static credentials associated with CVE-2026-20316 to achieve root access.

    Cisco has released the same Secure FMC hot fixes for CVE-2026-20079 and says there are no workarounds that fully address the vulnerability.

    BleepingComputer contacted Cisco to clarify whether the vulnerabilities are connected, whether CVE-2026-20079 has also been exploited, and whether the shared indicator was added to both advisories intentionally.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks Cisco Credential Exploited Flaw FMC static warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

    Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

    When AppSec Scanners Become a Supply Chain Attack Vector

    Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    Hugging Face Hack Lessons for Cyber Defenders

    How MFA gets hacked — and strategies to prevent it

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What ‘mAh’ means for your phone’s battery, and why I focus on another metric instead

    July 29, 2026

    Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

    July 29, 2026

    ARK Analyst Says Crypto Entering Biggest Consolidation Phase

    July 29, 2026

    Can’t sleep in the heat? These 8 tricks could save your night

    July 29, 2026
    Latest Posts

    Who’s in Andy Burnham’s new Labour cabinet?

    July 22, 2026

    Streeting apologises after early prisoner release comments heard on mic

    July 22, 2026

    Mehr Risikokapital, mehr Rüstung – Reiches Start-up-Plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What ‘mAh’ means for your phone’s battery, and why I focus on another metric instead

    July 29, 2026

    Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

    July 29, 2026

    ARK Analyst Says Crypto Entering Biggest Consolidation Phase

    July 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.