- Description
- A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.
- Source
- psirt@cisco.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- Severity
- CRITICAL
- psirt@cisco.com
- CWE-290
- Hype score
- Not currently trending
🔴 Cisco, ISE ve Secure Firewall ürünlerinde çok sayıda kritik güvenlik açığını yayınladı! • CVE-2026-76460 — CVSS 10.0: Cisco ISE authentication bypass. Kimlik doğrulaması gerektirmiyor ve aktif olarak sömürülüyor. • CVE-2026-76423 — CVSS 10.0: ISE/
@ridvanyagli
17 Sept 2026
353 Impressions
0 Retweets
2 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨 Cisco ISE API Authentication Bypass (CVE-2026-76423, CVSS 10.0) Reaches Admin Access Critical Vulnerability Alert! Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector is affected by CVE-2026-76423. 🔍 Identify Targets via ZoomEye: Search Dork: app="C
@zoomeyebot
17 Sept 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes