Authentication Bypass Flaw in Cisco Identity Services Engine
CVE-2026-76460

10CRITICAL

Key Information:

Badges

🔥 Trending now📈 Trended📈 Score: 4,820👾 Exploit Exists🦅 CISA Reported📰 News Worthy

What is CVE-2026-76460?

CVE-2026-76460 is a critical vulnerability found in the Cisco Identity Services Engine (ISE), a software solution designed for identity and access control within network environments. This vulnerability stems from insufficient authentication controls on an API endpoint within the ISE, which allows an unauthenticated, remote attacker to bypass authentication mechanisms. By exploiting this flaw, an attacker could send a specially crafted request to the affected API, leading to unauthorized access to the ISE. This breach could permit attackers to manage and manipulate sensitive network access configurations and authentication settings, posing significant security risks to organizations relying on Cisco ISE for network security and user management.

Potential Impact of CVE-2026-76460

  1. Unauthorized Access: The primary consequence of this vulnerability is the possibility of unauthorized access to critical network resources. An attacker could navigate the system without legitimate credentials, allowing them to alter authentication settings or extract sensitive data.

  2. Compromised Network Security: By bypassing the security measures implemented by the Cisco ISE, attackers could modify security policies, leading to a weakened overall security posture. This could enable further attacks within the network or exploitation of connected systems.

  3. Data Breaches and Exposure: With control over authentication processes, attackers could potentially access confidential user data and organizational information stored within the system, leading to data breaches, regulatory penalties, and reputational damage for the affected organization.

CISA has reported CVE-2026-76460

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-76460 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0 p8

Cisco Identity Services Engine Software 3.1.0 p9

Cisco Identity Services Engine Software 3.3 Patch 2

News Articles

Cisco Warns of Active Exploitation of Critical ISE Flaw

Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation

1 day ago

Unauthenticated attackers are bypassing Cisco ISE's management interface (CVE-2026-76460) - Help Net Security

Cisco confirmed attackers are hitting CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE).

1 day ago

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco ISE CVE-2026-76460 is under active exploitation; successful exploitation may yield root command execution.

1 day ago

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 📈

    Vulnerability started trending

  • 📰

    First article discovered by SecurityWeek

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.