BDS Threat Advisory: Cisco Secure Firewall Management Center Vulnerabilities

J Ellis July 31, 2026 Threat Notices

Overview

Our Cybersecurity SOC partner has flagged one newly disclosed vulnerability and one updated vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. Cisco Secure FMC is the centralized management platform for Cisco firewall estates, making a compromise a high-impact event with broad downstream consequences across an organization’s network.

Vulnerability Details

  • CVE-2026-20316 | CVSS 5.3 Medium | Static Credential Vulnerability — Exposes static credentials embedded in the FMC web interface, allowing an unauthenticated attacker to log in and access sensitive data. Cisco confirms this flaw can be chained with other FMC vulnerabilities to escalate to full privileges.
  • CVE-2026-20079 | CVSS 10.0 Critical | Unauthenticated Authentication Bypass / Remote Code Execution — An unauthenticated remote attacker can send crafted HTTP requests to the FMC web interface, bypass authentication due to an improper boot-time process, and execute arbitrary scripts with root privileges on the underlying operating system.

Both vulnerabilities affect on-premises Cisco Secure FMC Software regardless of device configuration.

How Could This Be Exploited?

Security management platforms like Cisco Secure FMC frequently operate with elevated privileges and extensive visibility into an organization’s network, making them attractive targets for adversaries seeking to weaken defensive controls. An attacker exploiting CVE-2026-20316 could log in using exposed static credentials and chain that access with other FMC vulnerabilities to escalate to full administrative privileges. CVE-2026-20079 is more severe on its own — it requires no authentication at all and can lead to full remote code execution with root-level access on the underlying system.

Is There Active Exploitation?

Yes, in part. Cisco has confirmed that CVE-2026-20316 is being actively exploited in the wild, and it has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation of CVE-2026-20079 has not been confirmed at the time of writing, but given its critical severity and unauthenticated attack path, it should be treated as an urgent patching priority.

What We’re Doing

Security technologies frequently operate with elevated privileges and broad visibility, making them attractive targets for adversaries seeking to weaken defensive controls. Our Cybersecurity SOC partner aligns its monitoring with the behaviors commonly observed following compromise of trusted security infrastructure and will continue to provide updates as new information becomes available.

Recommendations

  • Immediate Action: Apply the available Cisco Secure FMC hot fixes for your release train (7.0, 7.2, 7.4, 7.6, 7.7, or 10.0) immediately.
  • Restrict FMC management interface access to trusted internal networks and authorized IP ranges — do not expose the management interface to the public internet.
  • Run cat /var/log/messages | grep license in expert mode and check for entries containing /var/tmp/license.tmp, which may indicate prior exploitation of CVE-2026-20316.
  • If exploitation is suspected, rotate all credentials, keys, and certificates on the affected FMC device and contact Cisco TAC for recovery assistance.
  • Verify patch deployment across all managed environments running on-premises Cisco Secure FMC.

References

Questions or Concerns?

If you have any questions about this advisory or would like help verifying your patch status, please contact your Black Diamond Solutions account team.