CVE-2026-76460
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- Published Sep 16, 2026
- CVSS 10.0 critical
- 14.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks The Hacker News ·
- Cisco Zero-Day Highlights API Endpoint Authentication Issues Dark Reading ·
- Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) – CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460 Canadian Centre for Cyber Security ·
- Cisco security advisory (AV26-932) Canadian Centre for Cyber Security ·
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks The Hacker News ·
- Multiple vulnerabilities in Cisco products CERT-FR ·
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA ·