Cisco FMC static-credential flaw actively exploited
A Cisco Firewall Management Center vulnerability exploiting static credentials is being actively exploited, exposing data and bypassing security policy.
CERT-FR issued an advisory regarding CVE-2026-20316, a vulnerability affecting Cisco Firewall Management Center (FMC) across multiple version branches (7.0.x, 7.2.x, 7.4.x, 7.6.x, 7.7.x, and 10.0.x). The flaw stems from static credentials and allows an attacker to compromise data confidentiality and bypass the security policy enforced by the product.
Cisco has confirmed that this vulnerability is being actively exploited in the wild, per its security advisory cisco-sa-fmc-static-cred-BET3Cjh published July 29, 2026. Given that FMC is a central management platform for Cisco firewall deployments, exploitation could grant attackers unauthorized access or the ability to weaken security policies across managed firewall infrastructure. Affected organizations should apply the vendor-provided hotfixes for their respective FMC version as a priority.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0950
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free