Skip to content
Attackers exploit backdoor in Cisco's firewall management software

Attackers exploit backdoor in Cisco's firewall management software

Heise.De July 30, 2026

Attackers are currently targeting Cisco's Secure Firewall Management Center. The manufacturer has effectively left a backdoor in it through hardcoded credentials for an account, which malicious actors are now using to log into vulnerable instances.

The US cybersecurity authority CISA has added the vulnerability to its “Known Exploited Vulnerabilities” catalog. Cisco is responding with its own security advisory to the problem. The vulnerability affects the web interface of the Secure Firewall Management Center (FMC) software. Due to hardcoded credentials for a low-privilege account in the system, attackers can access the instances and sensitive data available on them from the network (CVE-2026-20316, CVSS 5.3 , Risk “ medium ”).

Cisco rated the impact as “ high ” risk, deviating from the pure CVSS rating. The reason given by employees is that the loophole can be combined with other vulnerabilities in the Secure FMC software to escalate privileges within the system. Without specifically naming this loophole, Cisco simultaneously updated a security advisory for a security vulnerability from March of this year , which allows the execution of scripts with root privileges (CVE-2026-20079, CVSS 10 , Risk “ critical ”). In it, Cisco adds the same software hotfixes and also names the IOCs. However, the section on exploits still lacks the statement that Cisco is unaware of any misuse on the network -- this is more of an indication that Cisco updated the report in haste.

While the risk is reduced if the FMC is not accessible from the public internet, Cisco discusses. However, there are no (temporary) countermeasures to contain the security vulnerability otherwise. Only updating to a corrected software version helps. Cisco provides the hotfixes for versions Cisco Firepower Management Center Hotfix_GB-7.0.9.1-3 and Secure Firewall Management Center Hotfix_HL-7.2.11.1-4, Hotfix_HG-7.4.7.1-3, Hotfix_CY-7.6.5.1-2, Hotfix_AM-7.7.12.1-2, and Hotfix_P-10.0.1.1-2 for download and installation. IT managers should apply the fixes immediately.

Since Cisco itself points to active exploitation of the vulnerability, administrators of the FMC software should assume that their installation has been compromised. The manufacturer also provides indicators of successful attacks (Indicators of Compromise, IOC). If certain entries in the logs indicate attacks, affected parties should request assistance from Cisco's Technical Assistance Center (TAC) for recovery.

Two weeks ago, CISA also warned of attacks on a vulnerability in Cisco products . This was a cross-site request forgery security vulnerability in Cisco's IOS operating system, which had been dormant in the code for 18 years.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.