What happened
Cisco has disclosed CVE-2026-20316, a static-credential vulnerability in the web interface of Cisco Secure Firewall Management Center Software. An unauthenticated remote attacker can use a low-privileged account to sign in to an affected device and access sensitive data. Cisco rates the advisory High because the flaw can be combined with other FMC vulnerabilities to elevate privileges, although its CVSS base score is 5.3.
Cisco says its Product Security Incident Response Team became aware of active exploitation in July. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 29 July on the basis of evidence of active exploitation. Neither source, however, describes the scale of the activity or identifies particular victims, so defenders should not invent certainty that the advisories do not provide.
[1][2]Who is affected
The advisory applies to Cisco Secure FMC Software regardless of device configuration. Cisco explicitly says that Cloud-Delivered FMC, Firewall Device Manager, Secure Firewall ASA Software, Secure Firewall Threat Defense Software and Security Cloud Control are not affected by this flaw.
Cisco has supplied hot fixes for the supported 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 release branches. There is no workaround. Teams should use Cisco's current advisory and Software Checker to map each deployed version to the correct fixed software, rather than treating a branch number alone as proof that a device is safe.
[1]What defenders should do now
First, identify every on-premises FMC instance, record its exact release and determine whether its management interface is reachable from the public internet or from less-trusted internal networks. Cisco notes that removing public internet access reduces the attack surface, but network restriction is not a substitute for installing the relevant hot fix.
Second, follow Cisco's advisory to apply the fixed software. Treat the change as an operational firewall-management update: confirm support, preserve the current configuration, plan rollback and verify management and policy deployment after maintenance. Do not expose the interface temporarily for convenience during the upgrade.
Finally, do not assume patching proves that earlier access did not occur. Cisco provides a device-log check in its advisory and says customers who suspect exploitation should contact Cisco TAC immediately for recovery assistance. Keep the review authorised and evidence-preserving; avoid ad-hoc testing against production management interfaces.
- Inventory on-premises FMC appliances and virtual instances, including standby and lab systems.
- Restrict management access to approved administrative routes and trusted source networks.
- Apply the Cisco hot fix or fixed release appropriate to the exact deployed branch.
- Review the vendor's current compromise guidance and escalate suspected exploitation to Cisco TAC.
- Retain relevant logs and change records so the investigation survives the maintenance window.
The Beekeeper view
Firewalls are often treated as protective infrastructure rather than ordinary software, which can leave their management planes outside normal application inventory and patch reporting. This incident is a useful correction: the console controlling a boundary device can itself be an internet-facing target.
For UK businesses, the practical question is whether the team can name every FMC instance, show who can reach it and prove which update it runs. Where active exploitation is confirmed, remediation has two tracks: close the vulnerability and establish whether the door was used while it was open.
[1][2]Primary sources
- Cisco Secure Firewall Management Center Software Static Credential Vulnerability — Cisco, 29 July 2026
- CISA Adds One Known Exploited Vulnerability to Catalog — US Cybersecurity and Infrastructure Security Agency, 29 July 2026
Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.