Skip to content

CVE-2026-76420 CVE-2026-76412 CVE-2026-76413

Cisco Secure Firewall Management Center root command execution and privilege escalation (CVE-2026-76420, CVE-2026-76412, CVE-2026-76413)

Critical 9.0 Vendor: Cisco Published

Three vulnerabilities in Cisco Secure Firewall Management Center: unauthenticated root command execution via AJP when sftunnel is down, SSO admin token forgery, and authenticated privilege escalation to root. Fixes are available; see Cisco's advisory for fixed builds.

What happened

Cisco's advisory describes three vulnerabilities in Cisco Secure Firewall Management Center (FMC). The most severe, CVE-2026-76420, has a CVSS v3.1 base score of 9 and is rated Critical by Cisco. An unauthenticated remote attacker can send crafted packets to the Apache JServ Protocol (AJP) connector when the valid sftunnel connection between FMC and Cisco Secure Firewall Threat Defense (FTD) software is down. A successful exploit could allow the attacker to execute commands as root and gain full control over the FMC REST APIs. Attack complexity is high, and no user interaction is required.

CVE-2026-76413 has a CVSS score of 8.2. An unauthenticated remote attacker can forge the Cisco Adaptive Security Device Manager (ASDM) single sign-on token to log in as the ASDM administrator. The attacker can repeat this action to keep legitimate administrators locked out indefinitely. CVE-2026-76412 has a CVSS score of 8.5 and requires valid credentials through the web-based management interface or REST API; a successful exploit could enable the remote diagnostics debugger and elevate privileges to root. Cisco rates all three vulnerabilities as Critical.

Cisco PSIRT states it is not aware of any public announcements or malicious use of these vulnerabilities. No KEV entry is listed.

Who is affected

These vulnerabilities affect Cisco Secure Firewall Management Center software. CVE-2026-76420 and CVE-2026-76413 affect builds 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.3, and 7.2.0. CVE-2026-76412 affects builds 7.7.0, 7.7.10, 7.7.10.1, 7.7.11, 7.7.12, 10.0.0, and 10.0.1. FMC is the central management console for Cisco Secure Firewall deployments; it typically holds firewall policy, device administration, and user access control, so root-level or administrator-level compromise can affect the entire managed firewall estate.

What to do now

  1. Identify affected FMC deployments. Compare running versions against the affected builds listed above.
  2. Patch as soon as possible. Cisco has published fixes, but no fixed release numbers are listed in this advisory; obtain the correct fixed build for your release train from Cisco's advisory.
  3. Do not rely on a workaround. Cisco states there are no workarounds that address these vulnerabilities.
  4. Until patched, restrict network access to the FMC management interface, ASDM, and AJP connector so only authorised management networks can reach them, and monitor administrative logins and privilege changes for unexpected activity.

How to detect it

Cisco has not published indicators of compromise for these vulnerabilities. As an immediate check, confirm whether affected FMC builds are present and whether the management, ASDM, and AJP interfaces are reachable from untrusted networks. Review administrative login and privilege-change history for unexpected sessions, because CVE-2026-76413 permits administrator login through token forgery and CVE-2026-76412 permits privilege elevation to root.

Beyond the patch

These are management-plane vulnerabilities in a security control, not just another application. If an FMC is reachable from untrusted segments, it becomes a route to firewall management. Virtual CISO Services can help verify management interfaces are not exposed and establish a patching cadence. Because this is Cisco software in your estate, Supply Chain Defense & Third-Party Risk helps track vendor advisories and fixed releases so a multi-CVE bundle like this is remediated before it becomes an incident.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-76420
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet
CVE-2026-76412
Cisco Secure Firewall Management Center (FMC)
7.7.0
7.7.10
7.7.10.1
7.7.11
10.0.0
7.7.12
10.0.1
No fixed version listed yet
CVE-2026-76413
Cisco Secure Firewall Management Center (FMC)
7.0.0
7.0.0.1
7.0.1
7.0.1.1
7.0.2
7.2.0
7.0.2.1
7.0.3
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.