Junglewise Threat Intelligence

CVE-2026-76412: Cisco Secure FMC privilege escalation in remote diagnostics debugger

CVE-2026-76412 · Severity: high · CVSS 8.5 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center (FMC) is the centralized management platform for enterprise firewall networks. A flaw in its remote diagnostics debugger allows authenticated users to escalate their privileges to root, potentially giving attackers complete control over the firewall management infrastructure and all protected networks downstream. An attacker with valid credentials can exploit this via the web interface or REST API to gain root access.

Technical details

CVE-2026-76412 is a privilege escalation vulnerability caused by improper privilege-level validation in the remote diagnostics debugger of Cisco Secure FMC. The vulnerability exists in the debugger's privilege checking logic when users invoke remote diagnostics functions. An authenticated remote attacker can exploit this by sending requests through the web-based management interface or REST API to enable the remote diagnostics debugger and grant themselves elevated privileges, ultimately achieving root-level access. The attack requires valid user credentials on the device and involves a multistage process, resulting in a high attack complexity rating. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Management Center

Timeline

  • 2026-09-16: disclosed

References

Related threats