
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76413 is a Single Sign-On (SSO) token forgery vulnerability in the Cisco Adaptive Security Device Manager (ASDM) SSO handler for Cisco Secure Firewall Management Center (FMC) Software. It allows an unauthenticated, remote attacker to forge session tokens and log in as the ASDM administrator user, and by repeating the action, lock out legitimate administrators indefinitely. The vulnerability affects Cisco Secure FMC Software across a wide range of versions from 7.0.0 through 10.0.1. It was publicly disclosed on September 16, 2026, and carries a CVSS v3.1 base score of 8.2 (High) (Cisco Advisory, GitHub Advisory).
The root cause is classified as CWE-1259 (Improper Restriction of Security Token Assignment), where the ASDM SSO token is improperly managed, allowing it to be forged by an external attacker. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity — meaning it is straightforward to exploit remotely. An attacker exploits this by crafting or forging a valid-looking SSO session token that the ASDM SSO handler accepts without proper validation, granting administrative access. The vulnerability is tracked under Cisco Bug ID CSCwu16965 and is part of a broader advisory (cisco-sa-fmc2-multivulns-HXgcqRG) covering multiple FMC vulnerabilities (Cisco Advisory).
Successful exploitation grants an unauthenticated remote attacker full administrative access to the Cisco ASDM interface on the affected FMC device, without requiring any credentials. The attacker can perform any administrative action available through ASDM, and by repeatedly forging tokens, can maintain exclusive control while denying access to legitimate administrators — effectively creating a denial-of-service condition for management operations. The CVSS score reflects a high availability impact and low integrity impact, with no direct confidentiality impact, though administrative control over a firewall management platform poses significant risk to the broader network security posture (Cisco Advisory, GitHub Advisory).
As of the disclosure date, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit code has been identified (Cisco Advisory). The EPSS score is currently 0.0, indicating low near-term exploitation probability. The vulnerability was reported by independent security researcher Nicholas Michael Kloster. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Cisco has released software updates that address CVE-2026-76413; there are no workarounds available. Administrators should use the Cisco Software Checker to identify the appropriate fixed release for their deployment. As interim measures, Cisco recommends monitoring for unauthorized administrative access attempts, implementing network segmentation to restrict ASDM access to authorized management networks only, and enabling logging and alerting on authentication events to detect token forgery attempts (Cisco Advisory).
The vulnerability was reported to Cisco by independent security researcher Nicholas Michael Kloster and was disclosed as part of a broader Cisco advisory covering multiple FMC vulnerabilities on September 16, 2026. Cisco PSIRT confirmed no public exploitation or announcements at the time of disclosure. No significant broader community or media commentary beyond standard vulnerability tracking sites has been identified at this time (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."