In plain language
What this advisory means
Cisco Secure Firewall Management Center (FMC) contains static credentials for a low-privileged account. A remote attacker who does not already have an account could use those credentials to sign in through the web interface and access sensitive data available to that account. Cisco rates the issue High because it can be combined with other FMC vulnerabilities to gain higher privileges.
Technical explanation
How the issue affects the environment
CVE-2026-20316 is a static-credential weakness (CWE-259) in the Cisco Secure FMC web interface. Exploitation requires network access to the management interface but does not require prior authentication or user interaction. A successful attacker obtains low-privileged access and can read sensitive data; Cisco's CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, with a base score of 5.3. Cisco assigned a High Security Impact Rating because the vulnerability may be chained with other Secure FMC vulnerabilities for privilege elevation. The vulnerability affects Secure FMC Software regardless of device configuration, although removing public internet access from the management interface reduces the attack surface.
Operational impact
Why teams should care
An attacker could obtain unauthorized low-privileged access to FMC and expose sensitive information. Chaining this issue with other FMC vulnerabilities could result in elevated privileges, increasing the potential impact on firewall management systems. Cisco reports ongoing active exploitation.
Immediate action
Apply the Cisco hot fix appropriate for the installed FMC release, or use the Cisco Software Checker to identify an applicable fixed software release and upgrade to it. Cisco strongly recommends upgrading because active exploitation is ongoing. If exploitation is suspected, contact Cisco TAC for recovery assistance. At a minimum, Cisco recommends rotating all user credentials, keys, and certificates on the affected FMC device.
Affected and fixed releases
Temporary risk reduction
Cisco states that no workaround addresses this vulnerability. Preventing public internet access to the FMC management interface reduces the attack surface, but this is a mitigation and does not remediate the static credentials.
Evidence and validation checklist
- Inventory Cisco Secure FMC deployments and record their installed software releases.
- Use the Cisco Software Checker or the advisory's hot-fix table to select the applicable remediation.
- Determine whether each FMC management interface is publicly accessible; removing public internet access reduces exposure but is not a fix.
- In expert mode, run: cat /var/log/messages | grep license
- Review matching output for a command referencing /var/tmp/license.tmp; Cisco states that its presence may indicate exploitation.
- If exploitation is suspected, contact Cisco TAC for recovery assistance.
- Rotate all FMC user credentials, keys, and certificates as Cisco recommends in light of ongoing exploitation.
- Verify installation of the applicable Cisco hot fix or upgrade to a fixed software release.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
