Press TechRound interviews Secure.com CEO on the future of AI security
Read

A Firewall’s Own Master Key Just Fell Into the Wrong Hands

Attackers are exploiting a Cisco FMC static credentials flaw. CISA orders federal patching by Aug 1. See how to check for compromise.

Dateline: July 30, 2026

CISA Gives Agencies Days to Kill a Cisco FMC Flaw

Firewalls are supposed to keep attackers out. This week, one of the tools that manages them handed intruders a way in. Cisco confirmed attackers are already exploiting a hidden login built into its Secure Firewall Management Center.

What Happened?

Cisco warned that a static credentials flaw in its Secure Firewall Management Center, known as CVE-2026-20316, is being exploited right now. FMC is the console that controls many Cisco firewalls at once across a network. That makes it a high value target.

The problem is simple and old. A low privilege account with fixed, built in credentials was shipped inside the software. Anyone who knows those credentials can log in from a distance without any password of their own. No credentials to steal. No phishing needed. The keys were already inside.

Cisco flagged the flaw as High severity even though its technical score sits at a modest 5.3. The reason is chaining. On its own, the account only reaches low level data. Combined with other FMC bugs, it can open the door to bigger access and deeper control.

CISA added the flaw to its Known Exploited Vulnerabilities list on July 29.

Federal civilian agencies were ordered to fix it by August 1 and to check whether attackers had already used it. Cisco says its response team spotted active exploitation this month and has shipped hotfixes. There is no workaround, only the fix.

What’s the Impact?

FMC does not guard one machine. It manages fleets of firewalls. A foothold there can ripple across an entire network of defenses.

There is a second worry. Cisco updated a related advisory the same day for a critical authentication bypass bug that scores a perfect 10 and can hand an attacker root access. Both advisories now point to the same indicator of compromise. That overlap raises a real risk that attackers could combine the two for full system control.

Cisco named the weak point clearly. The web based management interface is where attackers keep slipping in. If that interface is exposed to the public internet, the risk climbs sharply.

How to Avoid This

  • Apply the Cisco hotfix now. There is no substitute and no workaround.
  • Pull the FMC management interface off the public internet. Cisco says this alone shrinks the attack surface.
  • Check your system logs for signs of compromise using the indicators below.
  • If you find evidence of exploitation, rotate every credential, key, and certificate on the device, then contact Cisco support for recovery help. Cisco recommends full rotation because the attacks are ongoing.