The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation.
The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems.
“This vulnerability is due to the presence of static user credentials for a low-privileged account,” Cisco said in an alert released Wednesday. “An attacker could exploit this vulnerability by using the account to log in to an affected system.”
“A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.”
Cisco noted that the attack surface that is associated with the vulnerability is reduced if the FMC management interface does not have public internet access. The network equipment company also said it’s assigning it a Security Impact Rating (SIR) of High rather than Medium due to the fact that it can be chained with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Security researcher Jimi Sebree of Horizon3.ai has been credited with discovering and reporting the flaw. Cisco also acknowledged that it became actively exploited earlier this month, although it did not disclose when the attacks began, who is behind them, or how the vulnerability is being exploited in these efforts.
The issue has been addressed in the following hot fix versions of Cisco Secure FMC Software –
As indicators of compromise (IoCs), Cisco is urging customers to use the “cat /var/log/messages | grep license” CLI command in expert mode. If the command output includes “/var/tmp/license.tmp,” there is a possibility that the vulnerability may have been exploited on the Cisco Secure FMC device –
Leave a Reply