CVE-2026-76460 is a critical (CVSS 10.0) authentication bypass vulnerability in Cisco Identity Services Engine (ISE) affecting a REST API endpoint, allowing unauthenticated remote attackers to gain full administrative access to the device without any credentials or user interaction. The flaw stems from insufficient authentication controls (CWE-648) on an API endpoint and has been confirmed actively exploited in the wild by Cisco PSIRT and added to the CISA KEV catalog. Successful exploitation grants root-level access to the ISE management interface and underlying OS, enabling complete compromise of the network access control infrastructure.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-16
Added to CISA KEV: 2026-09-16 0 DAY BETWEEN CVE AND KEV
CVE-2026-76460 is a critical vulnerability affecting Cisco Identity Services Engine (ISE), stemming from insufficient authentication control on a REST API endpoint. This flaw is particularly significant because it allows an unauthenticated, remote attacker to bypass the web-based management interface and gain unauthorized access to the device with root-level privileges. Due to its maximum CVSS score of 10.0 and evidence of active exploitation in the wild, it represents a severe security risk to any network infrastructure utilizing affected Cisco ISE deployments.
An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.How the Attack Works. Tracked as CVE-2026-76460 , the flaw carries a maximum CVSS score of 10.0. The security advisory states , “This vulnerability is due t…
The Cisco PSIRT advisory confirms that CVE-2026-76460, an unauthenticated REST API authentication bypass, carries a CVSS score of 10.0 and is being leveraged by attackers in the wild. Cisco disclosed nine vulnerabilities in its Identity Services Engine (ISE) on September 16, 2026, including multiple…
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions ...
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing th…