Breaking: Cisco Secure FMC Hardcoded Credentials Exploited — 31 July 2026
Cisco Secure FMC Hardcoded Credentials Under Active Attack
Cisco has disclosed that CVE-2026-20316, a hardcoded credential vulnerability in Secure Firewall Management Center (FMC), is being actively exploited by attackers in the wild. The flaw allows unauthenticated remote attackers to log in using a low-privilege built-in account and access sensitive system data.
Vulnerability Details
Cisco assigned this a High severity rating despite a CVSS score of 5.3 because the credentials enable access that can be chained with additional FMC vulnerabilities to escalate privileges. Cisco reports awareness of active exploitation beginning in July 2026, though the company has not disclosed when attacks started, who is behind them, or which organizations have been targeted. The reporting researcher is Jimi Sebree of Horizon3.ai.
The vulnerability affects all on-premises Secure FMC deployments (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) regardless of configuration. Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, and Security Cloud Control are not impacted.
What This Means
No workarounds exist. FMC instances exposed to the internet are immediately at risk. Even internal-only deployments are vulnerable if any administrator's workstation is compromised. The hardcoded credentials mean every FMC installation is equally exposed — this is not a misconfiguration issue.
Attack surface is reduced if the FMC management interface is not internet-facing, but this provides only a speed bump, not genuine protection against insiders or compromised internal systems.
Recommended Actions for CISOs
1. Immediate: Verify whether your FMC instances are internet-exposed. If yes, apply patches now or isolate systems until patches are deployed. 2. Forensics: Search /var/log/messages for "license" entries. Unauthorized logins using the hardcoded account are the primary detection method. 3. Patching: Cisco has released hot fixes for all supported versions. Schedule deployment within the next 48 hours. 4. Privilege audit: Review what the compromised low-privilege account can access in your environment. If it reaches critical assets (routing, logging, policy data), elevation risk is immediate.
The fact that Cisco is not disclosing attack scope suggests widespread exploitation. Treat this as active threat, not routine vulnerability management.

