Privilege Escalation Vulnerability in Cisco Secure FMC Software
CVE-2026-76412

8.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-76412?

A vulnerability exists in the remote diagnostics debugger of Cisco Secure FMC Software, allowing authenticated remote attackers to enable the remote diagnostics debugger service. This flaw arises from improper privilege level checks for users invoking remote diagnostics, potentially permitting the attackers to escalate their privileges to root after authenticating via the web-based management interface or REST API. Successful exploitation of this vulnerability requires valid user credentials and involves a complex, multistage process.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.7.0

Cisco Secure Firewall Management Center (FMC) 7.7.10

Cisco Secure Firewall Management Center (FMC) 7.7.10.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.