Cisco Rated Its Own Exploited FMC Bug 5.3. Your Patch Queue Should Ignore That Number

by Rebecca Sutton

Cisco gave its own Cisco FMC vulnerability a CVSS score of 5.3. Then it called the bug High severity anyway. That contradiction sits right there in the same advisory. It says more about the state of vulnerability scoring than most vendors admit out loud.

Close-up of hands typing a fix on a laptop keyboard, addressing the Cisco FMC vulnerability

CVE-2026-20316 is now confirmed under active exploitation. It sits on CISA’s Known Exploited Vulnerabilities catalogue. CISA added it on 29 July 2026, with a 1 August deadline for US federal agencies. This Cisco FMC vulnerability affects Cisco Secure Firewall Management Center, the console that controls policy across an organisation’s whole firewall estate. The score most patch tools use to triage it puts the bug in the “get to it eventually” pile.

Why the score misses the point of this Cisco FMC vulnerability

CVSS measures a flaw on its own. It struggles with context, and context is what makes this bug dangerous. A static, low-privilege credential built into every FMC install isn’t scary because of what that one account can do alone. It’s scary because of what it opens up next.

Cisco says as much in its own advisory. The flaw gets worse “when chained with other bugs.” That’s Cisco admitting the 5.3 score is only part of the picture. Most patch queues aren’t built to read between those lines. The account sits in FMC Software releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. Its credentials never change between installs. That’s why an attacker who knows them can just walk in, no password needed.

A firewall manager is not a normal internal system

IT teams often treat management interfaces as lower risk than the systems they manage. The thinking goes: nobody outside the organisation should ever reach them. Cisco’s advisory cuts that assumption down directly. Exposure exists “regardless of device configuration.”

Even where that assumption held up, it was always fragile. An attacker can get inside a network through a phishing email or a leaked credential. A different unpatched device works too. Once they’re in, a management console with reach over every firewall becomes one of the most valuable things they can find. Treating it as low priority because it isn’t internet-facing was always a bet, not a control. That’s why testing what an attacker can reach once they’re already inside your network matters as much as testing the perimeter. Cisco is clear on scope too. Cloud-Delivered FMC, Firepower Device Manager and Secure Firewall ASA Software escape this particular bug. The exposure is specific to on-premises FMC.

What Cisco isn’t saying yet

Jimi Sebree of Horizon3.ai gets the credit for reporting the flaw. But Cisco has stayed quiet on how many organisations were hit, who is running the attacks, or exactly when exploitation began. That gap is normal for a fresh KEV entry. It still cuts against any temptation to assume this is a small, low-volume campaign. Absence of detail is not evidence of absence of victims.

The pattern is familiar. Edge and management devices keep landing on CISA’s exploited list faster than organisations can patch them, as the SonicWall SMA 1000 zero-days earlier this year showed. The one concrete thing Cisco did publish is a rough indicator of compromise. Run cat /var/log/messages | grep license in FMC’s expert mode. A reference to /var/tmp/license.tmp in the output suggests the account was used. It’s a blunt signal, not a forensic report, but it’s the only one available. Running it costs a few minutes.

How this Cisco FMC vulnerability should change your triage

If your organisation still ranks patches mainly by CVSS number, pin this advisory above the ticketing queue. A 5.3 with no workaround and active exploitation deserves fast action. So does a KEV listing. Together, they beat plenty of 8s and 9s sitting in systems nobody can currently reach. It’s the same lesson behind why vendor severity ratings keep falling behind real-world attacks. The number on the advisory and the risk to your business are related. They are not the same thing.

Cisco’s own guidance backs this up. Patch immediately across every affected branch, from 7.0 through the newest 10.0 release. Check the log indicator above. Rotate every credential, key and certificate on the box afterwards. That is not the guidance Cisco gives for routine bugs. It is the guidance for a flaw the vendor knows is worse than its own score suggests. That’s exactly why there’s no workaround this time, only a hotfix.

The real lesson

Score-driven patch queues aren’t wrong so much as incomplete. They handle scale well and judgement poorly. A flaw like this one sits right in that gap. Scoring systems still don’t weigh what a bug enables, only what it does alone. Until that changes, catching bugs like this one falls to a person reading the advisory closely, not a number sorting a spreadsheet.

If you run on-premises FMC, don’t wait for the score to catch up with reality on this Cisco FMC vulnerability. Patch it this week. Treat the CVSS number as one input among several, not the whole decision.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like