The U.S. Cybersecurity and Infrastructure Security Agency has added a Cisco Secure Firewall Management Center vulnerability to its known exploits catalog after attackers were found leveraging hardcoded login credentials against deployed instances of the platform.
Security researcher Jimi Sebree of Horizon3.ai identified the issue, cataloged as CVE-2026-20316, in FMC’s browser-based administration panel. The built-in credentials grant access to a restricted account, though Cisco warned that combining this bug with other weaknesses could let adversaries gain broader system privileges for more invasive assaults on firewall infrastructure.
Engineering teams at Cisco confirmed spotting real-world abuse of the flaw this month and shipped emergency repair packages. The company published a forensic marker for defenders: the execution of a script named package_info.pl referencing /var/tmp/license.tmp in log files indicates a compromised system. Customers are advised to replace all passwords, encryption keys, and digital certificates on affected FMC appliances.
This marks the third time this year that FMC’s web console has drawn attacker attention. Two earlier critical vulnerabilities, an authentication bypass tracked as CVE-2026-20079 and a code execution flaw tracked as CVE-2026-20131, were disclosed in March. The Interlock ransomware crew was caught exploiting the latter as a zero-day beginning in late January.
Restricting administrative consoles from direct internet exposure remains an effective defense, Cisco stated in its advisories for all three FMC bugs, though the company has not indicated whether the current exploitation campaign relies on externally reachable management ports.
