Junglewise Threat Intelligence

CVE-2026-76413: Cisco Secure FMC SSO token forgery in ASDM handler

CVE-2026-76413 · Severity: high · CVSS 8.2 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewall deployments. A vulnerability in its single sign-on system allows unauthenticated attackers to forge administrator credentials, gaining unauthorized access and potentially locking out legitimate administrators from management functions indefinitely.

Technical details

The vulnerability exists in the ASDM (Adaptive Security Device Manager) SSO token handler within Cisco Secure FMC Software, stemming from improper management and validation of SSO tokens. An unauthenticated, remote attacker can exploit this by performing session token forgery techniques to impersonate the ASDM administrator user without valid credentials. The attack has no preconditions (no authentication required) and is network-reachable. Successful exploitation grants full administrator access and enables attackers to prevent legitimate administrators from accessing the system through repeated login cycles. Cisco has released software patches to address this vulnerability, and no workarounds are available.

Affected products

  • Cisco Secure Firewall Management Center Multiple versions (see Cisco advisory for specific affected releases)

Timeline

  • 2026-09-16: disclosed: Cisco Security Advisory cisco-sa-fmc2-multivulns-HXgcqRG published

References

Related threats