What happened this week
On July 29, 2026, Cisco published Cisco Security Advisory cisco-sa-fmc-static-cred-BET3Cjh disclosing CVE-2026-20316, a use of hard-coded password vulnerability in the web interface of Cisco Secure Firewall Management Center. Later the same day, CISA added the CVE to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline of August 1, 2026 — three days from disclosure. Cisco PSIRT confirmed active exploitation in July 2026.
This is the third network security management platform CISA has added to KEV in a nine-day window (Check Point SmartConsole on July 22, Arista VeloCloud Orchestrator on July 27, Cisco FMC on July 29). Any Hawaii business running network-security management consoles reachable from untrusted networks is now inside a well-documented attacker pattern.
Why this one matters even at CVSS 5.3
NVD scores CVE-2026-20316 as CVSS 5.3 (Medium) because the hard-coded account is low-privileged and provides read-only access to sensitive data. Cisco assigned Security Impact Rating "High" anyway, and the reason is printed directly in the advisory: the flaw "can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges." The low-privileged read is a ladder rung, not the destination. A companion advisory revised the same day — CVE-2026-20079, an authentication bypass allowing unauthenticated root command execution — carries CVSS 10.0.
Practically: there is no exploit to write. An attacker who knows the built-in credentials logs in through the web interface and reads sensitive data off the box that manages the firewall estate. No brute force, no credential stuffing, no phishing. Cisco has published the same Indicators of Compromise for both CVEs; the same hotfix per release patches both. If FMC 7.0 through 7.7 or 10.0 is running in your environment, treat CVE-2026-20316 and CVE-2026-20079 as one project.
How this shows up for a Hawaii business
Cisco Secure Firewall (formerly Firepower) is used by mid-market Hawaii businesses that outgrew SonicWall or Meraki tiers, by state and county agencies, by Hawaii healthcare systems consolidating branch firewalls, and by managed service providers that standardized on Cisco for their multi-site clients. FMC is the centralized console; it typically runs on-premises in a data center or colocation rack rather than at each site. Two common Hawaii deployment patterns:
- Single FMC managing 5-40 Firepower/FTD appliances across neighbor-island branches. A hospitality group, healthcare organization, or professional services firm with locations on Oahu, Maui, Kauai, and Hawaii Island typically has one FMC in a Honolulu data center pushing policy to each site's edge firewall.
- MSP-hosted FMC serving multiple client tenants. If your Hawaii MSP uses on-premises FMC to manage your firewall (and dozens of other clients on the same appliance), CVE-2026-20316 is their problem to patch, but the low-privileged read gives the attacker recon data on every tenant.
The 30-second question for a Hawaii business today: is your FMC management interface reachable from the internet? Third-party scans found 12 to 26 internet-exposed FMC instances worldwide as of the disclosure date. If yours is one of them, close the exposure at the perimeter today — before patching.
Recommended response for a Hawaii business (48-hour plan)
Hour 0-24: Contain
- Confirm inventory. Log into every Cisco Secure Firewall Management Center in the environment (or your MSP's environment on your behalf) and record the version from Help → About.
- Determine internet exposure. Check the perimeter firewall rules, cloud NAT, and reverse-proxy configuration for any inbound path to the FMC management interface on HTTPS 443 or 8305. If any exposure exists, block it immediately. Restrict FMC management to an internal management VLAN or jump host reachable only over VPN.
- Run the Indicator-of-Compromise check. From FMC expert mode, execute the Cisco-supplied command: cat /var/log/messages | grep license. If output references /var/tmp/license.tmp, escalate to your MSP or Cisco TAC and treat the FMC as compromised until forensic triage completes.
- Review authentication logs on the FMC web interface for successful logins to low-privileged accounts from source IPs that do not correspond to legitimate administrator activity, especially in the window preceding July 29, 2026 (pre-disclosure exploitation is confirmed).
Hour 24-72: Patch
- Match your FMC version to the Cisco fixed release for CVE-2026-20316 in the advisory. Hotfixes are available for 7.0, 7.2, 7.4, 7.6, and 7.7. FMC 7.3 does not have a hotfix — upgrade to a supported train.
- Download the signed hotfix tar archive from Cisco Software Center. Upload without extraction. Package verification takes several minutes; clear unused packages first if the FMC UI is sluggish.
- Confirm the same hotfix also covers CVE-2026-20079 (root command execution, CVSS 10.0). Cisco is issuing a single hotfix per release that patches both CVEs.
- After patching, if any IoCs were found in step 3, rotate all user credentials, cryptographic keys, and certificates on the FMC. Rebuild high-privilege accounts and audit all firewall policy changes made in the preceding 60 days.
What Hawaii MSPs should be telling their clients this week
If your Hawaii MSP manages your Cisco Secure Firewall, expect a written status update this week that answers three questions: (1) is your FMC affected, (2) has the hotfix been applied, and (3) has the IoC check been run and what did it show. If your MSP has not proactively raised CVE-2026-20316 by end of business Thursday July 30, that is a signal about their advisory response process worth remembering. A silent MSP during a KEV-level Cisco advisory with a three-day federal deadline is not the MSP a Hawaii business wants managing its firewall estate.
For a decision-stage frame on Hawaii MSP selection, see the Honolulu MSP evaluation framework. For diligence questions to ask a Hawaii MSP before signing, see questions to ask a Hawaii MSP before signing.
The larger pattern this month
CVE-2026-20316 is the seventh network-security-appliance CVE added to CISA KEV in July 2026, joining Check Point SmartConsole (CVE-2026-16232, added July 22), Arista VeloCloud Orchestrator (CVE-2026-16812, added July 27), Fortinet FortiOS (CVE-2025-68686, added July 27), and multiple SharePoint deserialization RCEs. The management-plane pattern is consistent: internet-exposed administrative consoles for security products remain one of the highest-value initial access vectors, and vendors are disclosing under active-exploitation pressure with shorter federal remediation windows than the traditional 21-day BOD 22-01 baseline (Cisco FMC got three days).
For a broader framing on how a Hawaii business should think about firewall selection when the management plane itself is the attack surface, see the Hawaii MSP quote line-item decoder. For a related advisory response from earlier this month, see the Check Point SmartConsole advisory.
Why HI Tech Hui is publishing this
HI Tech Hui has been the managed IT and cybersecurity provider for Hawaii businesses since 2014, operating from 401 Kamakee Street in Kakaako with a Cyberuptive-run security operations capability. When a KEV-listed hardcoded credential lands on the box that manages a Hawaii business's firewall estate with a three-day federal deadline, the honest thing to publish is the practical response — not a pitch. Every Hawaii Cisco Secure Firewall customer deserves the containment steps, the IoC command, and the hotfix path, whether we manage that estate or someone else does.
Frequently asked questions
What should a Hawaii business do about the Cisco Secure Firewall FMC hardcoded credentials advisory (CVE-2026-20316)?
A Hawaii business running Cisco Secure Firewall Management Center (FMC) should immediately (1) check whether the FMC web interface is exposed to the public internet and block that exposure at the perimeter, (2) confirm the FMC version and apply Cisco's hotfix for CVE-2026-20316, and (3) run the Indicator-of-Compromise check in /var/log/messages for /var/tmp/license.tmp entries. CISA added CVE-2026-20316 to the Known Exploited Vulnerabilities catalog on July 29, 2026 with a federal remediation deadline of August 1, 2026.
What is CVE-2026-20316?
CVE-2026-20316 is a use of hard-coded password vulnerability (CWE-259) in the web interface of Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center. An unauthenticated remote attacker can log in using a built-in low-privileged account whose credentials are fixed in the shipping product. NVD scores it CVSS 5.3 (Medium) but Cisco assigns Security Impact Rating High because the access can be chained with other FMC vulnerabilities to escalate privileges.
Which Cisco FMC versions are affected by CVE-2026-20316?
Affected versions include FMC 7.0.0 through 7.0.9, 7.2.0 through 7.2.11, 7.3.0 through 7.3.1.2, 7.4.0 through 7.4.7, 7.6.0 through 7.6.5, 7.7.0 through 7.7.12, and 10.0.0 through 10.0.1. Cisco has hotfixes for 7.0, 7.2, 7.4, 7.6, and 7.7 (not 7.3 — upgrade to a supported train). Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, and Security Cloud Control are not affected.
When did CISA add CVE-2026-20316 to the KEV catalog?
CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, 2026, the same day Cisco published the advisory. The federal remediation deadline under Binding Operational Directive 22-01 is August 1, 2026 — a three-day window. Private organizations are not bound by the federal deadline but should treat KEV additions as immediate patch priorities regardless of CVSS score.
How can a Hawaii business check if its Cisco FMC has been exploited?
From FMC expert mode, run: cat /var/log/messages | grep license. If log entries reference /var/tmp/license.tmp, the device may have been compromised. This is the Indicator of Compromise Cisco published in the advisory. If IoCs are found, Cisco advises contacting Technical Assistance Center for recovery guidance and immediately rotating all user credentials, cryptographic keys, and certificates on that FMC before returning to service.
Should a Hawaii business without internet-exposed FMC still patch CVE-2026-20316?
Yes. Cisco confirms the attack surface is reduced when the FMC management interface is not internet-exposed, but the hard-coded credentials still exist inside the environment. An insider or a compromised endpoint on the management network can still use the built-in credentials to obtain the low-privileged foothold. Patch all affected FMC instances within 7 days regardless of exposure; prioritize internet-facing instances for immediate action.
What is the difference between CVE-2026-20316 and CVE-2026-20079?
CVE-2026-20316 (published July 29, 2026) is a hardcoded low-privileged credential flaw scored CVSS 5.3 but SIR High. CVE-2026-20079 (originally published March 2026, updated July 29) is an authentication bypass allowing unauthenticated root-level command execution, scored CVSS 10.0. Both affect FMC on-premises, both have the same Indicators of Compromise, and Cisco's single hotfix per release addresses both vulnerabilities at once.
What other CISA KEV additions should Hawaii businesses know about in July 2026?
July 2026 KEV additions relevant to Hawaii businesses: Cisco Secure FMC (CVE-2026-20316, added July 29), Fortinet FortiOS (CVE-2025-68686, added July 27), Arista VeloCloud Orchestrator (CVE-2026-16812, added July 27), Check Point SmartConsole (CVE-2026-16232, added July 22), and SharePoint (CVE-2026-50522, added July 22). All are network security or firewall management platforms; any Hawaii business running these should confirm patch status.
Bottom line
CVE-2026-20316 is a hard-coded password in a Cisco Secure Firewall Management Center login screen. There is no exploit to write — an unauthenticated attacker just logs in. CISA gave federal agencies three days. A Hawaii business running affected FMC (7.0, 7.2, 7.3, 7.4, 7.6, 7.7, or 10.0) should close internet exposure of the management interface today, apply Cisco's hotfix within 72 hours, and run the /var/tmp/license.tmp IoC check before patching. If your MSP has not raised this by end of business Thursday, ask why.