
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76412 is a privilege escalation vulnerability in the remote diagnostics debugger of Cisco Secure Firewall Management Center (FMC) Software that allows an authenticated, remote attacker to elevate privileges to root. It affects Cisco Secure FMC Software versions 7.7.0, 7.7.10, 7.7.10.1, 7.7.11, 7.7.12, 10.0.0, and 10.0.1. The vulnerability was publicly disclosed on September 16, 2026, as part of a multi-vulnerability advisory (cisco-sa-fmc2-multivulns-HXgcqRG). It carries a CVSS v3.1 base score of 8.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is an improper privilege level check (CWE-285: Improper Authorization) when a user invokes the remote diagnostics debugger feature of Cisco Secure FMC Software. An attacker with valid low-privileged credentials can authenticate via the web-based management interface or the REST API and abuse the remote diagnostics debugger to grant themselves elevated privileges, ultimately achieving root access. The exploitation requires a multistage process, which is reflected in the High Attack Complexity rating. Cisco Bug ID CSCwu12566 tracks this issue (Cisco Advisory).
Successful exploitation allows a low-privileged authenticated attacker to escalate to root on the affected Cisco Secure FMC appliance, resulting in complete compromise of confidentiality, integrity, and availability. With root access, an attacker could manipulate firewall policies, exfiltrate sensitive network configuration data, pivot to managed Firepower Threat Defense (FTD) devices, or disrupt security operations across the managed network. The scope is marked as Changed, indicating that the impact extends beyond the FMC itself to resources it manages (Cisco Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable due to the requirement for valid user credentials and a multistage attack process. The vulnerability was reported by independent security researcher Nicholas Michael Kloster (Cisco Advisory).
Cisco has released software updates that address this vulnerability; there are no workarounds available. Organizations should upgrade to a fixed release of Cisco Secure FMC Software as identified via the Cisco Software Checker. As interim hardening measures, restrict network access to the FMC web-based management interface and REST API to trusted administrative networks only, enforce strong authentication controls, and audit user permissions regularly. Monitor for suspicious use of remote diagnostics features until patching is complete (Cisco Advisory).
Cisco's Product Security Incident Response Team (PSIRT) confirmed at the time of disclosure that it was not aware of any public announcements or malicious use of this vulnerability. The vulnerability was credited to independent security researcher Nicholas Michael Kloster. No significant public commentary or media coverage beyond the official advisory has been identified at this time (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."