Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-76413
Cisco Secure Firewall Management Center vulnerability analysis and mitigation

Overview

CVE-2026-76413 is a Single Sign-On (SSO) token forgery vulnerability in the Cisco Adaptive Security Device Manager (ASDM) SSO handler for Cisco Secure Firewall Management Center (FMC) Software. It allows an unauthenticated, remote attacker to forge session tokens and log in as the ASDM administrator user, and by repeating the action, lock out legitimate administrators indefinitely. The vulnerability affects Cisco Secure FMC Software across a wide range of versions from 7.0.0 through 10.0.1. It was publicly disclosed on September 16, 2026, and carries a CVSS v3.1 base score of 8.2 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-1259 (Improper Restriction of Security Token Assignment), where the ASDM SSO token is improperly managed, allowing it to be forged by an external attacker. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity — meaning it is straightforward to exploit remotely. An attacker exploits this by crafting or forging a valid-looking SSO session token that the ASDM SSO handler accepts without proper validation, granting administrative access. The vulnerability is tracked under Cisco Bug ID CSCwu16965 and is part of a broader advisory (cisco-sa-fmc2-multivulns-HXgcqRG) covering multiple FMC vulnerabilities (Cisco Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker full administrative access to the Cisco ASDM interface on the affected FMC device, without requiring any credentials. The attacker can perform any administrative action available through ASDM, and by repeatedly forging tokens, can maintain exclusive control while denying access to legitimate administrators — effectively creating a denial-of-service condition for management operations. The CVSS score reflects a high availability impact and low integrity impact, with no direct confidentiality impact, though administrative control over a firewall management platform poses significant risk to the broader network security posture (Cisco Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit code has been identified (Cisco Advisory). The EPSS score is currently 0.0, indicating low near-term exploitation probability. The vulnerability was reported by independent security researcher Nicholas Michael Kloster. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Cisco Secure FMC instances running vulnerable software versions (7.0.0 through 10.0.1) using network scanning tools such as Shodan, Censys, or Nmap targeting ASDM/FMC management ports.
  2. Identify ASDM SSO endpoint: Locate the ASDM SSO handler endpoint on the target FMC instance, which is responsible for processing SSO authentication tokens.
  3. Forge SSO token: Craft a forged or manipulated ASDM SSO session token by exploiting the improper token management logic — leveraging the lack of proper token validation or binding to forge a token accepted as belonging to the administrator user.
  4. Submit forged token: Send the crafted token to the ASDM SSO handler endpoint via an HTTP/HTTPS request, bypassing authentication and gaining a session as the ASDM administrator.
  5. Maintain access / lock out admins: Repeat the token forgery process to continuously hold the administrator session, preventing legitimate administrators from logging in and effectively locking them out of ASDM indefinitely (Cisco Advisory).

Indicators of compromise

  • Network: Unexpected or repeated authentication requests to the ASDM SSO handler endpoint from unknown or external IP addresses; unusual administrative sessions originating from unfamiliar source IPs.
  • Logs: FMC authentication logs showing successful ASDM administrator logins from unexpected IP addresses or at unusual times; repeated login events without corresponding legitimate administrator activity; legitimate administrator login failures coinciding with unauthorized sessions.
  • Process/Session: Multiple concurrent ASDM administrator sessions, or sessions that persist without corresponding user activity; legitimate administrators reporting inability to log in to ASDM despite correct credentials.

Mitigation and workarounds

Cisco has released software updates that address CVE-2026-76413; there are no workarounds available. Administrators should use the Cisco Software Checker to identify the appropriate fixed release for their deployment. As interim measures, Cisco recommends monitoring for unauthorized administrative access attempts, implementing network segmentation to restrict ASDM access to authorized management networks only, and enabling logging and alerting on authentication events to detect token forgery attempts (Cisco Advisory).

Community reactions

The vulnerability was reported to Cisco by independent security researcher Nicholas Michael Kloster and was disclosed as part of a broader Cisco advisory covering multiple FMC vulnerabilities on September 16, 2026. Cisco PSIRT confirmed no public exploitation or announcements at the time of disclosure. No significant broader community or media commentary beyond standard vulnerability tracking sites has been identified at this time (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Firewall Management Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20344HIGH8.8
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76412HIGH8.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-76413HIGH8.2
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20342HIGH7.7
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026
CVE-2026-20343HIGH7.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management