Improper Restriction of Security Token Assignment in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2026-76413
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper management of the Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) token. A remote attacker can perform session token forgery techniques to log in as the administrator user and keep legitimate administrators locked out of the ASDM indefinitely.