CVE-2026-20316: Cisco FMC Backdoor Account Actively Exploited -- Patch Before August 1

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
Cisco disclosed an actively exploited static credential backdoor in Secure Firewall Management Center on July 29, 2026 -- the centralized management platform that controls firewall policies, VPN configurations, and intrusion prevention rules across enterprise and government Cisco Firepower deployments worldwide.
CVE-2026-20316 is a hardcoded low-privilege account compiled directly into Cisco Secure Firewall Management Center (FMC) Software across six version branches: 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Any unauthenticated remote attacker with network access to the FMC management interface can log in using these built-in credentials, access sensitive firewall configuration data, and establish a foothold inside the management plane of your entire network security estate. Cisco assigned a High Security Impact Rating to this Cisco FMC static credential vulnerability despite its CVSS 5.3 score because CVE-2026-20316 chains directly with CVE-2026-20079, a maximum CVSS 10.0 authentication bypass that executes arbitrary commands as root on the FMC appliance via specially crafted HTTP requests.
CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, 2026, citing active zero-day exploitation confirmed by Cisco's Product Security Incident Response Team, and set an August 1 remediation deadline for all U.S. federal civilian executive branch agencies -- that is tomorrow. Cisco published advisory cisco-sa-fmc-static-cred-BET3Cjh the same day with branch-specific hotfixes addressing CVE-2026-20316, CVE-2026-20079, and a third critical vulnerability CVE-2026-20131. No workaround exists. The only remediation is applying the correct hotfix for your FMC version branch.
If your Cisco FMC management interface is accessible from any external IP address, treat your environment as potentially compromised until the hotfix is confirmed installed and the exploitation IOC check returns clean.
How Does CVE-2026-20316 Work in Cisco Secure FMC?
CVE-2026-20316 is a use of hard-coded password vulnerability (CWE-259) in the web management interface of Cisco Secure Firewall Management Center Software. A static set of credentials for a low-privilege user account is compiled directly into FMC Software across all affected release branches. Any attacker who possesses these credentials and can reach the FMC management interface over the network can authenticate without any authorization from the system owner or any knowledge of the organization's configured user accounts.
The mechanism is direct: when the FMC web application processes authentication requests, it accepts the compiled-in credentials as valid regardless of the authentication policy configured by administrators. The attacker does not guess or brute-force the credential. It exists in every unpatched FMC instance and is not affected by password rotation policies, because the credential is embedded in the application binary rather than stored in the user database.
Successful exploitation of CVE-2026-20316 alone grants the attacker low-privilege access to FMC's management interface. From that session, the attacker can enumerate firewall policies across all managed Firepower Threat Defense (FTD) sensors, read VPN gateway configurations, identify downstream managed device inventory, and access network topology data that maps the organization's entire Cisco security architecture.
What transforms this from a medium-severity misconfiguration into a critical exposure path is the chain with CVE-2026-20079. The hardcoded credential provides guaranteed authenticated access; the CVSS 10.0 authentication bypass converts that access into full root command execution. Advisory cisco-sa-fmc-static-cred-BET3Cjh, published July 29, 2026, addresses both vulnerabilities with the same branch-specific hotfixes. Security researcher Jimi Sebree at Horizon3.ai is credited with the CVE-2026-20316 discovery.
CVE-2026-20079: The CVSS 10.0 Escalation Path to Root Access
CVE-2026-20079 is a second vulnerability in Cisco Secure FMC disclosed in the same July 29, 2026 advisory. It carries the maximum possible CVSS score of 10.0. Where CVE-2026-20316 provides authenticated low-privilege access via static credentials, CVE-2026-20079 is a pre-authentication bypass that allows any unauthenticated remote attacker to execute arbitrary commands as root on the Linux-based FMC appliance by sending specially crafted HTTP requests.
The vulnerability stems from an improper system process created during FMC appliance boot. Cisco originally disclosed CVE-2026-20079 in March 2026 and updated the advisory on July 29 to add a second bug ID, branch-specific hotfixes, and indicators of compromise for both vulnerabilities together. CVE-2026-20131, a third critical FMC vulnerability disclosed in the same advisory bundle, carries the same CVSS 10.0 rating and was confirmed exploited by AWS threat intelligence reporting as of July 29, 2026.
With root access achieved via CVE-2026-20079, an attacker controls the FMC operating system and all firewall policy decisions made by downstream FTD sensors. The attacker can modify access control policies to open inbound access rules, disable intrusion prevention system signatures against specific traffic, suppress security event logging to remove forensic visibility, and deploy persistent backdoors to maintain access after patching.
The chained attack path -- CVE-2026-20316 providing the initial authenticated foothold, CVE-2026-20079 escalating to root -- is the scenario CISA's KEV addition reflects. An attacker targeting an internet-exposed FMC management interface does not need phishing, does not need a supply chain compromise, and does not need any prior access to the organization. Review our SonicWall SMA1000 zero-day analysis for a directly parallel case of management interface exploitation against a network security appliance.
Reconnaissance: Identify Internet-Exposed FMC Interfaces
Attacker scans for internet-accessible Cisco FMC management interfaces on TCP ports 443, 4505, and 8305 using Shodan queries or passive scanning. Affected versions 7.0 through 10.0 can be fingerprinted by version-specific banner strings before any authentication attempt.
Authentication with Static Credential (CVE-2026-20316)
Attacker logs into the FMC web interface using the hardcoded static credential compiled into all affected FMC versions. No password guessing, brute force, or prior access required. Access is granted to a low-privilege account with read access to FMC configuration data, managed device inventory, and network topology.
Environment Enumeration via FMC Management Interface
Attacker reads firewall access control policies, VPN gateway configurations, managed Firepower Threat Defense sensor inventory, and network topology data using the low-privilege FMC session. This data identifies downstream FTD sensors and the network segments they protect for targeted policy modification.
Root Command Execution via CVE-2026-20079 (CVSS 10.0)
Attacker sends specially crafted HTTP requests to the FMC management interface, bypassing authentication entirely via CVE-2026-20079 and executing arbitrary commands as root on the Linux-based FMC appliance. This achieves operating-system-level control over the FMC and all downstream firewall policy decisions.
Firewall Policy Modification and Persistence
With root access to the FMC, attacker modifies managed firewall policies across all downstream FTD sensors: opening inbound access rules, disabling IPS signatures, suppressing security event logging, creating new management accounts, or deploying a persistent backdoor to maintain access after the static credential hotfix is applied.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Who Is at Risk? Cisco FMC Deployment Scope
Cisco Secure Firewall Management Center is the centralized policy and event management platform for Cisco Firepower Threat Defense deployments. Organizations use FMC to configure firewall access control policies, IPS rulesets, VPN gateways, SSL decryption policies, and network access control across their entire Cisco Firepower sensor estate from a single management plane. FMC is deployed across federal government agencies, financial institutions, healthcare systems, and large enterprise networks as a tier-1 network security management system.
The six affected version branches -- 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 -- span every actively supported Cisco FMC release line as of July 2026. Any organization running an unpatched FMC on these releases is vulnerable to CVE-2026-20316 regardless of whether the management interface is internet-exposed. An attacker with access to the management VLAN, a compromised internal workstation, or a VPN connection can exploit the static credential from inside the perimeter.
Internet-exposed FMC management interfaces are the highest-risk configuration. RunZero's analysis of the vulnerability confirms that misconfigured FMC deployments with management ports reachable from external IP addresses are the primary active exploitation target. Cisco's advisory explicitly states that reducing the attack surface means restricting management interface access to trusted networks -- the FMC management interface should never accept connections from internet-facing IPs.
The exploitation IOC -- a /var/tmp/license.tmp entry in /var/log/messages showing the www process invoking package_info.pl as root -- applies to all six affected version branches. Running this check on every FMC appliance takes under one minute and confirms whether the static credential was used before the hotfix was applied.
Sigma Detection Rules for Cisco FMC Post-Exploitation Activity
No CVE-specific Sigma detection rule exists in the SigmaHQ library for CVE-2026-20316 or CVE-2026-20079 as of July 31, 2026 -- expected for vulnerabilities with active exploitation confirmed two days ago. Cisco FMC runs on a hardened Linux-based appliance, and the best available Sigma coverage targets post-exploitation behavior that attackers exhibit after achieving root access via CVE-2026-20079: Linux reconnaissance and history tampering to cover tracks.
Both rules below require Linux process creation audit logs from the FMC appliance forwarded to your SIEM. Enable syslog forwarding from FMC via System > Configuration > Syslog in the management interface. Run in detection mode for 24 hours to baseline expected FMC administrative activity before enabling alerts.
The primary IOC check for this vulnerability is host-based, not SIEM-based: run cat /var/log/messages | grep license on each FMC appliance and look for any entry containing /var/tmp/license.tmp showing the www process invoking package_info.pl as root. This is the confirmed exploitation indicator from Cisco advisory cisco-sa-fmc-static-cred-BET3Cjh. Any hit confirms that CVE-2026-20316 was exploited on that appliance. Rotate all credentials and contact Cisco TAC before returning any positive-IOC appliance to production.
Subscribe to unlock Sigma Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Subscribe to unlock WAF Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Confirmed Indicators of Compromise
The primary exploitation indicator for CVE-2026-20316 is a host-based log entry, not a network IOC. Cisco advisory cisco-sa-fmc-static-cred-BET3Cjh documents a single confirmed IOC: a log entry in /var/log/messages containing the string /var/tmp/license.tmp, specifically showing the www process invoking package_info.pl as root. Run the following command on every Cisco FMC appliance in your environment immediately:
cat /var/log/messages | grep license
Any output matching the pattern of the www user executing package_info.pl with sudo and referencing /var/tmp/license.tmp confirms that CVE-2026-20316 was exploited on that appliance. If found, immediately rotate all user credentials, API keys, VPN certificates, and integration credentials on the affected FMC and engage Cisco TAC for forensic recovery support. Do not return any IOC-positive appliance to production without verification that no downstream firewall policies were modified.
No public network IOCs (IP addresses, domains, or file hashes) have been attributed to the current CVE-2026-20316 campaign as of July 31, 2026. The attack uses compiled-in credentials rather than external infrastructure visible in network logs. Add a SIEM alert for the www user executing package_info.pl or any sudo commands referencing /var/tmp in FMC syslog output. Correlate with unexpected inbound connections to FMC management ports (TCP 443, 4505, 8305) from any IP address outside your defined management VLAN range.
Subscribe to unlock Indicators of Compromise
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Patch Before August 1: Cisco FMC Remediation Steps
Seven steps to close this gap before the weekend. The CISA August 1 deadline applies to federal agencies, but the same urgency applies to any organization running Cisco FMC -- active exploitation began before July 29 and no workaround exists.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Why Cisco FMC Static Credential CVE-2026-20316 Matters for Your Organization
Cisco Secure Firewall Management Center is not just another enterprise application. It is the administrative control plane for network security itself. Compromising the FMC does not give an attacker access to one server or one application. It gives them control over the security policies governing traffic across every network segment, every remote VPN user, and every protected workload in your entire Cisco Firepower deployment.
The attack path created by CVE-2026-20316 and CVE-2026-20079 is particularly dangerous because it eliminates all the defensive friction that normally slows attackers down. There is no phishing email to train users to recognize. There is no exploit payload that endpoint detection can flag. There is no novel technique that threat intelligence needs to identify. The attacker uses credentials that Cisco compiled into the product and sends HTTP requests to an interface the product is designed to accept. The defense is entirely a patch management and network segmentation problem -- and both can be resolved today.
The CISA August 1 deadline reflects the Known Exploited Vulnerabilities program working as designed: once active exploitation is confirmed, the remediation window for covered agencies compresses to days. Non-federal organizations should apply the same logic. Three days is an appropriate patch window for a management plane vulnerability with confirmed zero-day exploitation. If your FMC management interface is accessible from any external IP address today, that window started before you read this post.
The pattern repeats across network security management products. The SonicWall SMA1000 zero-day and the Qilin ransomware PAN-OS exploitation campaign both demonstrated that management interfaces for network security devices attract targeted attack effort precisely because they sit above the security controls, not inside them. An attacker who controls the FMC controls the firewall, and the firewall controls everything behind it. Patching, segmenting, and continuously monitoring these management planes is the non-negotiable baseline.
The bottom line
Cisco FMC static credential CVE-2026-20316 is actively exploited, added to the CISA KEV catalog July 29, and carries a federal patch deadline of August 1 -- tomorrow. Apply the branch-specific hotfix from advisory cisco-sa-fmc-static-cred-BET3Cjh immediately: FMC 10.0 requires P-10.0.1.1-2, FMC 7.7 requires AM-7.7.12.1-2, FMC 7.6 requires CY-7.6.5.1-2, FMC 7.4 requires HG-7.4.7.1-3, FMC 7.2 requires HL-7.2.11.1-4, and FMC 7.0 requires GB-7.0.9.1-3. Run the IOC check first on every FMC: cat /var/log/messages | grep license. A positive hit means full credential rotation is required before returning the appliance to service. Block all external access to FMC management ports at the network perimeter today.
This analysis is generic. create a free account to score threats like this against your own stack.
Frequently asked questions
What is CVE-2026-20316 in Cisco Secure Firewall Management Center?
CVE-2026-20316 is a use of hard-coded password vulnerability in Cisco Secure Firewall Management Center Software. A static credential for a low-privilege account is compiled directly into FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Any unauthenticated remote attacker with network access to the FMC management interface can use this credential to log in and access firewall configuration data. CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, 2026, following confirmed active exploitation. Cisco rated it High Security Impact despite a CVSS 5.3 score due to the escalation chain with CVE-2026-20079, which carries a maximum CVSS 10.0 rating.
How do I check if my Cisco FMC has been exploited by CVE-2026-20316?
Run this command on each Cisco FMC appliance: cat /var/log/messages | grep license. Look for any log entry containing /var/tmp/license.tmp showing the www process invoking package_info.pl as root. This is the confirmed exploitation indicator documented in Cisco advisory cisco-sa-fmc-static-cred-BET3Cjh. Any match confirms CVE-2026-20316 was exploited on that appliance. If found, rotate all credentials, keys, and certificates immediately and contact Cisco TAC for recovery assistance before returning the device to production.
What hotfixes patch CVE-2026-20316 and CVE-2026-20079 in Cisco FMC?
Cisco released branch-specific hotfixes on July 29, 2026. FMC 10.0 requires hotfix P-10.0.1.1-2. FMC 7.7 requires AM-7.7.12.1-2. FMC 7.6 requires CY-7.6.5.1-2. FMC 7.4 requires HG-7.4.7.1-3. FMC 7.2 requires HL-7.2.11.1-4. FMC 7.0 requires GB-7.0.9.1-3. Download from the Cisco advisory using advisory ID cisco-sa-fmc-static-cred-BET3Cjh at sec.cloudapps.cisco.com. The same hotfixes address all three CVEs: CVE-2026-20316, CVE-2026-20079, and CVE-2026-20131. No workaround exists; patching is the only remediation.
Can CVE-2026-20316 lead to a complete firewall compromise?
Yes, when chained with CVE-2026-20079. CVE-2026-20316's static credential provides guaranteed low-privilege authenticated access to the FMC management interface. CVE-2026-20079, rated CVSS 10.0, allows an unauthenticated attacker to bypass authentication entirely and execute arbitrary commands as root on the FMC Linux appliance via crafted HTTP requests. An attacker who chains these two vulnerabilities gains operating-system-level control of the FMC and can modify firewall access control policies, disable IPS rules, suppress security event logging, and read all configuration data for every Firepower Threat Defense sensor managed by the FMC.
Is my Cisco Secure Firewall Management Center exposed to the internet?
Check by querying your perimeter firewall policies and security group rules for inbound access to TCP ports 443, 4505, and 8305 on all FMC management IP addresses from non-management-VLAN IPs. The FMC management interface should never be accessible directly from internet-facing addresses. Use runZero's asset discovery query (vendor:=Cisco AND product:=FMC) to enumerate all FMC instances in your environment and confirm their management interface IP addresses. Restrict access to a dedicated management VLAN or a jump host with multi-factor authentication before applying the hotfix.
What is a static credential vulnerability in network security devices?
A static credential vulnerability exists when a software vendor compiles a username and password directly into a product's binary code rather than requiring administrators to configure unique credentials during setup. The credentials cannot be changed or removed by end users and remain valid in every instance of the affected software version regardless of the organization's password policies. When discovered by security researchers or attackers, these credentials provide guaranteed access to any device running the vulnerable version. CVE-2026-20316 in Cisco FMC follows the same pattern as CVE-2024-20439 in Cisco Smart Licensing Utility and similar findings in other network security appliances.
What is the CISA deadline for patching CVE-2026-20316 in Cisco FMC?
CISA set August 1, 2026 as the remediation deadline for all U.S. federal civilian executive branch agencies under Binding Operational Directive 22-01. Agencies must apply Cisco's branch-specific hotfixes for all FMC instances under their management by that date. Non-federal organizations are not subject to BOD 22-01 deadlines but should treat the CISA KEV addition and confirmed active exploitation as requiring immediate patching. Waiting for a standard quarterly patch cycle is not appropriate for a management plane vulnerability with active zero-day exploitation underway.
How do the CVE-2026-20316 and CVE-2026-20079 vulnerabilities work together?
CVE-2026-20316 scores CVSS 5.3 because it grants only low-privilege access and does not independently enable full system compromise. CVE-2026-20079 scores the maximum CVSS 10.0 because it allows root command execution without any credentials via specially crafted HTTP requests. The combined attack chain starts with CVE-2026-20316's guaranteed low-privilege authentication to establish an initial foothold and enumerate the FMC environment, then uses CVE-2026-20079's root execution to escalate to full appliance control. Evaluating either vulnerability in isolation underestimates the actual risk. The practical attack chain severity is CVSS 10.0.
Sources & references
- Cisco Security Advisory cisco-sa-fmc-static-cred-BET3Cjh: CVE-2026-20316 and CVE-2026-20079
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-20316 Added July 29, 2026
- BleepingComputer: Cisco warns of FMC static credential flaw exploited in zero-day attacks
- runZero: Cisco Secure FMC vulnerability CVE-2026-20316 -- Find impacted assets
- SecurityWeek: Cisco Secure FMC Zero-Day Exploited in the Wild
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
