CVE-2026-76413
CVE-2026-76413 is a high-severity vulnerability with a CVSS 3.x base score of 8.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1259.
Key facts
- Severity: High (CVSS 3.x base score 8.2)
- EPSS exploit prediction: 0% (38th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1259
- Published:
- Last modified:
Description
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could exploit this vulnerability by performing session token forgery techniques. A successful exploit could allow the attacker to log in as the administrator user and, by repeating this action, keep legitimate administrators locked out of the ASDM indefinitely.
Frequently asked questions
- What is CVE-2026-76413?
- A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could exploit this vulnerability by performing session token forgery techniques. A successful exploit could allow the attacker to log in as the administrator user and, by repeating this action, keep legitimate administrators locked out of the ASDM indefinitely.
- How severe is CVE-2026-76413?
- CVE-2026-76413 has a CVSS 3.x base score of 8.2, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability high.
- Is CVE-2026-76413 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (38th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-76413?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-76413 published?
- CVE-2026-76413 was published on 2026-09-16 and last updated on 2026-09-18.
References
Other CWE-1259 vulnerabilities
- CVE-2024-36533 — Critical (CVSS 9.8): Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining…
- CVE-2026-54593 — High (CVSS 8.1): Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version…
- CVE-2024-29371 — High (CVSS 7.5): In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web…
- CVE-2026-25700 — High (CVSS 7.2): Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer:…
- CVE-2025-56207 — Medium (CVSS 6.5): A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an…
- CVE-2024-4598 — Medium (CVSS 6.5): An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich…