CVE-2026-76413
moderateAuthentication Bypass via SSO Token Forgery in Cisco ASDM for Secure FMC
Cisco Secure Firewall Management Center (FMC) Software contains a flaw in the Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler, caused by improper management of the ASDM SSO token (CWE-1259). An unauthenticated, remote attacker can exploit it by performing session token forgery techniques against the ASDM SSO login mechanism. A successful attack lets the attacker log in as the ASDM administrator without any credentials, and by repeatedly forging tokens they can keep legitimate administrators locked out of ASDM indefinitely, consistent with the high-availability impact reflected in the 8.2 CVSS score. Any organization running Cisco Secure FMC with ASDM SSO enabled is exposed, since no user interaction or prior access is required. As of now there is no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA KEV.
What to do: Upgrade Cisco ASDM and Cisco Secure FMC to the fixed releases identified in Cisco's advisory for CVE-2026-76413 (no fixed version numbers were provided in this data). Until patched, restrict ASDM and FMC management interfaces to trusted administrative networks or VPN access via access control lists, and monitor for unexpected ASDM administrator logins or repeated administrator lockouts, which could indicate token-forgery attempts.
| Cisco Adaptive Security Device Manager (ASDM) SSO handler for Cisco Secure Firewall Management Center (FMC) Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could exploit this vulnerability by performing session token forgery techniques. A successful exploit could allow the attacker to log in as the administrator user and, by repeating this action, keep legitimate administrators locked out of the ASDM indefinitely.
- Weakness
- CWE-1259
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.