Authentication Bypass in Cisco Secure FMC Software
CVE-2026-76413

8.2HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-76413?

A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) related to its single sign-on (SSO) handler can enable remote attackers to log in as the Cisco ASDM administrator. This flaw arises from improper handling of the SSO token, allowing malicious actors to employ session token forgery techniques. If exploited, this vulnerability could facilitate unauthorized access to administrator-level functionalities, effectively locking out legitimate administrators from the ASDM, thus posing a considerable risk to network security.

Affected Version(s)

Cisco Secure Firewall Management Center (FMC) 7.0.0

Cisco Secure Firewall Management Center (FMC) 7.0.0.1

Cisco Secure Firewall Management Center (FMC) 7.0.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.