INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco FMC Zero-Day Exploited by Lazarus Group

| 2026-07-30 05:08 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability, CVE-2026-20079, has been identified as a critical authentication bypass flaw in Cisco Secure FMC Software. This could potentially allow threat actors to execute arbitrary executable script files and gain root access on affected devices. The same indicators of compromise, including the presence of "/var/tmp/license.tmp" in command output, suggest that exploitation may be possible. Furthermore, Cisco has updated its advisory for this vulnerability, assigning it a Security Impact Rating (SIR) of High rather than Medium due to potential chaining with other vulnerabilities.
Technical Mitigations AI-generated
* Use the "cat /var/log/messages | grep license" CLI command in expert mode to detect and respond to potential exploitation of CVE-2026-20316 on Cisco Secure FMC Software. * Keep hot fix versions of Cisco Secure FMC Software up-to-date, specifically targeting 7.0, 7.2, 7.4, 7.6, and 7.7, as indicated by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). * Implement a secure login policy for all users on Cisco Secure FMC Software to minimize the risk of unauthorized access. * Regularly monitor system logs and network traffic for signs of exploitation or suspicious activity related to CVE-2026-20316, and take prompt action if necessary.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20316CVE-2026-20316 CVE-2026-20079CVE-2026-20079
Target & Sectors
Global Scope defensedefense
Incident Timeline
‎March 2026
Threat actors exploited a previously unknown vulnerability in Cisco FMC, targeting systems with CVE-2026-20079.
vulnerability CVE-2026-20079
general_metric 20079 CVE-2026
‎July 29
Threat actors exploited a previously undisclosed zero-day vulnerability in Cisco FMC, targeting systems with CVE-2026-20079.
vulnerability CVE-2026-20079
general_metric 20079 CVE-2026
‎Jul 30, 2026
Threat actors exploited the Cisco FMC Zero-Day vulnerability by using it to target the Cisco Secure FMC management interface.
infrastructure 7.0
infrastructure 7.0.9
infrastructure 7.2
infrastructure 7.2.11
infrastructure 7.4
infrastructure 7.4.7
infrastructure 7.6
infrastructure 7.6.5
infrastructure 7.7
infrastructure 7.7.12
infrastructure 10.0
infrastructure 10.0.1
organisation CLI
organisation the Cisco Secure FMC
organisation root@firepower:/home/admin# cat /var/log/messages
organisation tandem
organisation SIR
organisation Cisco Secure FMC
organisation FMC
organisation Cisco
‎July 2026
Threat actors exploited a zero-day vulnerability in Cisco FMC.
‎2026/07/30
A Cisco FMC device was compromised due to exploitation of a zero-day vulnerability caused by static credentials for a low-privilege account.
organisation Secure Firewall Management Center
organisation CVSS
organisation CVE-2026
infrastructure 7.0
infrastructure 7.2
infrastructure 7.4
infrastructure 7.6
infrastructure 7.7
infrastructure 10.0
organisation Secure FMC
organisation Critical FMC
organisation Cloud-Delivered FMC
organisation Secure Firewall ASA
organisation Cisco Secure FMC
organisation CVE-2026-20079
organisation BleepingComputer
organisation Actively Exploited
organisation FMC
organisation Cisco FMC
organisation IOC
organisation EDR
‎August 1, 2026
Threat actors exploited a zero-day vulnerability in Cisco FMC.
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎7.0.9
Software Version
Metrics
infrastructure
‎7.2
Software Version
Metrics
infrastructure
‎7.2.11
Software Version
Metrics
infrastructure
‎7.4
Software Version
Metrics
infrastructure
‎7.4.7
Software Version
Metrics
infrastructure
‎7.6
Software Version
Metrics
infrastructure
‎7.6.5
Software Version
Metrics
infrastructure
‎7.7
Software Version
Metrics
infrastructure
‎7.7.12
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎10.0.1
Software Version
Metrics
data_breach
7
Secure Software Cisco_Firepower_Mgmt_Center_Hotfix_Gb-7.0.9.1-3.Sh.Rel.Tar
Intelligence Sources