CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data
ID: 190de734-4e63-525b-8caf-ecef88396577
STIX ID: report--190de734-4e63-525b-8caf-ecef88396577
Feed Name: SOC Prime Blog
Cisco released emergency hot fixes for CVE-2026-20316, a static-credential vulnerability in Cisco Secure Firepower Management Center (FMC) that permits unauthenticated low-privilege access; Cisco elevated the severity because this foothold can be chained with other FMC bugs to escalate privileges, and CISA added it to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Cisco published hot fixes for multiple release branches, provided a detection artifact (grep for /var/tmp/license.tmp in /var/log/messages), stated no complete workaround exists, and advised immediate patching, restricting management access, forensic review, credential/key/certificate rotation, and contacting Cisco TAC if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
