Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316)

Vulnerability
First reported
Last updated
Happening score
H score 51
1 unique sources, 1 articles

Summary

Hide ▲

Cisco Secure FMC Software is exposed by CVE-2026-20316, a static credential flaw that was actively exploited in zero-day attacks to reach vulnerable devices. The issue lets an unauthenticated, remote attacker log in with built-in low-privilege credentials and access data available to that account. Cisco released hot fixes for affected Secure FMC releases and said there is no workaround that fully addresses the flaw.

Related Happenings

StrikeShark SharkLoader and Cobalt Strike Beacon campaign

Campaign
H score42 First: 26.06.2026 21:17 Last: 26.06.2026 21:17 Sources 1

About this happening: The StrikeShark campaign is deploying SharkLoader to load Cobalt Strike Beacon on compromised hosts, raising the risk of broader follow-on intrusion activity. It has t...

CISA urgent mitigation order for Cisco FMC CVE-2026-20131

Advisory/Mitigation
H score58 First: 23.03.2026 12:30 Last: 23.03.2026 12:30 Sources 1

About this happening: CISA ordered federal civilian agencies to patch CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) within three days or discontinue use if mitigat...

Interlock Cisco Secure Firewall Management Center zero-day exploitation wave

Exploitation Wave
H score59 First: 18.03.2026 18:53 Last: 18.03.2026 18:53 Sources 1

About this happening: A zero-day exploitation wave tied to Interlock has been hitting Cisco Secure Firewall Management Center (FMC), putting enterprise firewalls at risk before patching...

Cisco Secure Firewall Management Center (FMC) authentication bypass and RCE flaws (multiple vulnerabilities)

Vulnerability
H score59 First: 04.03.2026 21:12 Last: 04.03.2026 21:12 Sources 1

How related: Cisco also updated an advisory for a separate critical FMC authentication bypass vulnerability tracked as CVE-2026-20079, which has a maximum CVSS score of 10.0.

About this happening: Cisco Secure Firewall Management Center (FMC) has two maximum-severity flaws, CVE-2026-20079 and CVE-2026-20131, that can let unauthenticated attackers take ov...

Latest development: 30.07.2026 00:35

Cisco warned that CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The flaw stems from static credentials for a low-privilege account built into Cisco Secure FMC Software, letting an unauthenticated, remote attacker log in and access sensitive data available to that account, and Cisco said it became aware of active exploitation in July 2026.

Cisco SSL VPN and GlobalProtect credential-probing campaign

Campaign
H score32 First: 18.12.2025 06:10 Last: 18.12.2025 06:10 Sources 1

About this happening: A coordinated credential-based campaign is now probing Cisco SSL VPN and Palo Alto Networks GlobalProtect portals at scale, raising the risk of unauthorized access att...

Timeline

  1. 30.07.2026 00:35 2 articles · 1h ago

    Cisco warns of active zero-day exploitation in Secure FMC CVE-2026-20316

    Initial Disclosure

    Cisco warned that CVE-2026-20316, a static credential flaw in Cisco Secure Firewall Management Center (FMC) Software, was actively exploited in zero-day attacks that let unauthenticated remote attackers log in to vulnerable devices and access sensitive data available to the low-privilege account. Cisco said the issue affects Secure FMC regardless of device configuration, released hot fixes for releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0, noted there are no workarounds that address the vulnerability, and told administrators to review /var/log/messages for /var/tmp/license.tmp and rotate credentials, keys, and certificates if compromise is suspected.

    Show sources