Authentication Bypass Flaw in Cisco Identity Services Engine
CVE-2026-76460
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-76460?
CVE-2026-76460 is a critical vulnerability found in the Cisco Identity Services Engine (ISE), a software solution designed for identity and access control within network environments. This vulnerability stems from insufficient authentication controls on an API endpoint within the ISE, which allows an unauthenticated, remote attacker to bypass authentication mechanisms. By exploiting this flaw, an attacker could send a specially crafted request to the affected API, leading to unauthorized access to the ISE. This breach could permit attackers to manage and manipulate sensitive network access configurations and authentication settings, posing significant security risks to organizations relying on Cisco ISE for network security and user management.
Potential Impact of CVE-2026-76460
-
Unauthorized Access: The primary consequence of this vulnerability is the possibility of unauthorized access to critical network resources. An attacker could navigate the system without legitimate credentials, allowing them to alter authentication settings or extract sensitive data.
-
Compromised Network Security: By bypassing the security measures implemented by the Cisco ISE, attackers could modify security policies, leading to a weakened overall security posture. This could enable further attacks within the network or exploitation of connected systems.
-
Data Breaches and Exposure: With control over authentication processes, attackers could potentially access confidential user data and organizational information stored within the system, leading to data breaches, regulatory penalties, and reputational damage for the affected organization.
CISA has reported CVE-2026-76460
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-76460 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0 p8
Cisco Identity Services Engine Software 3.1.0 p9
Cisco Identity Services Engine Software 3.3 Patch 2
News Articles
Cisco Warns of Active Exploitation of Critical ISE Flaw
Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation
1 day ago
Unauthenticated attackers are bypassing Cisco ISE's management interface (CVE-2026-76460) - Help Net Security
Cisco confirmed attackers are hitting CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE).
1 day ago
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco ISE CVE-2026-76460 is under active exploitation; successful exploitation may yield root command execution.
1 day ago
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 📰
First article discovered by SecurityWeek
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved