Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76412
Cisco Secure Firewall Management Center vulnerability analysis and mitigation

Overview

CVE-2026-76412 is a privilege escalation vulnerability in the remote diagnostics debugger of Cisco Secure Firewall Management Center (FMC) Software that allows an authenticated, remote attacker to elevate privileges to root. It affects Cisco Secure FMC Software versions 7.7.0, 7.7.10, 7.7.10.1, 7.7.11, 7.7.12, 10.0.0, and 10.0.1. The vulnerability was publicly disclosed on September 16, 2026, as part of a multi-vulnerability advisory (cisco-sa-fmc2-multivulns-HXgcqRG). It carries a CVSS v3.1 base score of 8.5 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is an improper privilege level check (CWE-285: Improper Authorization) when a user invokes the remote diagnostics debugger feature of Cisco Secure FMC Software. An attacker with valid low-privileged credentials can authenticate via the web-based management interface or the REST API and abuse the remote diagnostics debugger to grant themselves elevated privileges, ultimately achieving root access. The exploitation requires a multistage process, which is reflected in the High Attack Complexity rating. Cisco Bug ID CSCwu12566 tracks this issue (Cisco Advisory).

Impact

Successful exploitation allows a low-privileged authenticated attacker to escalate to root on the affected Cisco Secure FMC appliance, resulting in complete compromise of confidentiality, integrity, and availability. With root access, an attacker could manipulate firewall policies, exfiltrate sensitive network configuration data, pivot to managed Firepower Threat Defense (FTD) devices, or disrupt security operations across the managed network. The scope is marked as Changed, indicating that the impact extends beyond the FMC itself to resources it manages (Cisco Advisory, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable due to the requirement for valid user credentials and a multistage attack process. The vulnerability was reported by independent security researcher Nicholas Michael Kloster (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-accessible Cisco Secure FMC instances running affected versions (7.7.0–7.7.12, 10.0.0–10.0.1) using network scanning or Shodan queries targeting FMC management interfaces.
  2. Credential Acquisition: Obtain valid low-privileged user credentials for the target FMC, either through phishing, credential stuffing, or insider access.
  3. Authentication: Log in to the FMC web-based management interface or authenticate via the REST API using the acquired credentials.
  4. Invoke Remote Diagnostics Debugger: Access the remote diagnostics debugger feature through the management interface or REST API endpoint, exploiting the insufficient privilege check to enable the debugger service.
  5. Privilege Escalation: Use the remote diagnostics debugger to grant the attacker's account elevated privileges, ultimately achieving root-level access on the FMC appliance.
  6. Post-Exploitation: With root access, manipulate firewall policies, access sensitive configurations, or pivot to managed FTD devices (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or repeated REST API calls to remote diagnostics debugger endpoints from low-privileged accounts; unexpected API authentication events from non-administrative user accounts.
  • Logs: FMC audit logs showing low-privileged users invoking remote diagnostics features; privilege change events or root-level activity attributed to non-administrative accounts in system logs.
  • Process: Unexpected processes or commands executed under the root context on the FMC appliance not initiated by administrators.
  • File System: Unauthorized modifications to FMC configuration files or policy objects; new files or scripts created in privileged directories by non-root service accounts.

Mitigation and workarounds

Cisco has released software updates that address this vulnerability; there are no workarounds available. Organizations should upgrade to a fixed release of Cisco Secure FMC Software as identified via the Cisco Software Checker. As interim hardening measures, restrict network access to the FMC web-based management interface and REST API to trusted administrative networks only, enforce strong authentication controls, and audit user permissions regularly. Monitor for suspicious use of remote diagnostics features until patching is complete (Cisco Advisory).

Community reactions

Cisco's Product Security Incident Response Team (PSIRT) confirmed at the time of disclosure that it was not aware of any public announcements or malicious use of this vulnerability. The vulnerability was credited to independent security researcher Nicholas Michael Kloster. No significant public commentary or media coverage beyond the official advisory has been identified at this time (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Firewall Management Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20344HIGH8.8
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76412HIGH8.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76413HIGH8.2
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20342HIGH7.7
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20343HIGH7.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management