CVE-2026-76460

Published Sep 16, 2026

Last updated 13 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-76460 is an authentication bypass vulnerability found in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This flaw stems from insufficient authentication control on a specific API endpoint. An unauthenticated, remote attacker can exploit this vulnerability by sending a specially crafted request to the affected API endpoint. Successful exploitation allows the attacker to bypass the web-based management interface and gain unauthorized access to the affected device. The vulnerability impacts Cisco ISE and ISE-PIC releases 3.0 through 3.5.

Description
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Source
psirt@cisco.com
NVD status
Analyzed
Products
identity_services_engine, identity_services_engine_passive_identity_connector

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Exploit added on
Sep 16, 2026
Exploit action due
Sep 19, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@cisco.com
CWE-648

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

19

  1. 🔴 Cisco, ISE ve Secure Firewall ürünlerinde çok sayıda kritik güvenlik açığını yayınladı! • CVE-2026-76460 — CVSS 10.0: Cisco ISE authentication bypass. Kimlik doğrulaması gerektirmiyor ve aktif olarak sömürülüyor. • CVE-2026-76423 — CVSS 10.0: ISE/

    @ridvanyagli

    17 Sept 2026

    267 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. Attackers exploited CVE-2026-76460 (Cisco ISE API) and CVE-2026-87886 (Acronis Backup permissions) to compromise identity and backup infrastructure. TRC analysis shows how compromised identity services enabled lateral movement through unencrypted east-west traffic. #ZeroTrust

    @aviatrixtrc

    17 Sept 2026

    62 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA added Cisco ISE CVE-2026-76460 (CVSS 10.0 API bypass), Acronis CVE-2026-87886, and Pixel CVE-2026-58704 to KEV. Patch ISE first. https://t.co/UtfjbYxz58 https://t.co/QC14eBVf0C #2workly

    @2Workly

    17 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Cisco ISE CVSS 10 auth bypass (CVE-2026-76460) is being exploited NOW. Unauth remote hit on management API; CISA KEV, short patch clock. If you run ISE/ISE-PIC: patch to fixed 3.x builds today and hunt access.log. #CyberSecurity #CVE #ZeroDay Link: https://t.co/scwpSc1uKI

    @Orion84x

    17 Sept 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA added Cisco ISE CVE-2026-76460 (CVSS 10.0 API bypass) and Acronis CVE-2026-87886 to KEV. Source:… https://t.co/UtfjbYxz58 https://t.co/QC14eBVf0C

    @2Workly

    17 Sept 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🐦 🚨 Cisco ISE auth bypass (CVE-2026-76460, CVSS 10.0) actively exploited in the wild — unauthenticated attackers get root. Cisco SEG SQLi (CVE-2026-76461, CVSS 9.8) also under active attack via crafted emails. Patch both now. #infosec #CVE #Cisco

    @ita_ipo

    17 Sept 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Cisco warns of active exploitation of CVE-2026-76460, a max-severity auth bypass in Cisco ISE and ISE-PIC. Emergency patches are available, with no workaround and guidance to check for compromise. #CiscoISE #CVE-2026-76460 #CISA https://t.co/wvksRavyyY

    @TweetThreatNews

    17 Sept 2026

    230 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Critical Cisco ISE Vulnerability Exposes Networks to Unauthenticated Takeover A maximum-severity CVSS 10.0 API vulnerability in Cisco ISE (CVE-2026-76460) lets unauthenticated attackers bypass management… Full write-up → link in bio #cybersecurity #infosec #cve #kev #cisco

    @HotaSamit

    17 Sept 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Cisco released 15 advisories covering 42 vulnerabilities in Identity Services Engine. Six advisories rated Critical, including CVE-2026-76460 that permits management API authentication bypass and root command execution. ISE-PIC is also impacted. Exploitation confirmed in the

    @WorldCyberNewsX

    17 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【サイバーセキュリティ動向分析】 1. Cisco ISEの認証バイパス脆弱性(CVE-2026-76460、CVSS 10.0)が実害用 背景 Cisco Identity Services https://t.co/coYhl3bfER

    @kenebeii

    17 Sept 2026

    3908 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 CVE-2026-76460 (CVSS 10.0): Cisco Identity Services Engine Authentication Bypass Exploited in the Wild Critical Vulnerability Alert! Cisco Identity Services Engine (ISE) and ISE-PIC is affected by CVE-2026-76460. 🔍 Identify Targets via ZoomEye: Search Dork: app="Cisco

    @zoomeyebot

    17 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 CISCO SEPTEMBER 2026 HARDENING — 20+ CVEs, CVSS 10.0 ×4 Cisco ISE: 4 critical flaws + 7 more CVE-2026-76460 ACTIVELY EXPLOITED — CISA KEV NO WORKAROUNDS. PATCH NOW. → https://t.co/1DyvK8x2Pu #Cisco #CVE #CVSS10 #PatchNow #CyberSecurity #CyberSecurity #ThreatInte

    @ThreatAft

    17 Sept 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. CISA adds CVE-2026-76460 in Cisco ISE and CVE-2026-87886 in Acronis Backup to the KEV catalog. CVE-2026-76460 lets unauthenticated attackers bypass the ISE web interface via weak API authentication. CVE-2026-87886 enables privilege escalation through overly permissive defaults

    @WorldCyberNewsX

    17 Sept 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🔒 #CyberSecurity CVE-2026-76460: Cisco ISE Privileged API Exploitation in the Wild — Detection a… "CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities (KEV) catalog on…" 🔗 https://t.co/iEaGLkTWf3 #CyberSecurity #ThreatIntel #cve202676460 #critical #ci

    @SecurityAr58409

    17 Sept 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CISA Adds Two Known Exploited Vulnerabilities to Catalog(CISA、悪用が確認された2件の脆弱性をKEVカタログに追加) #CISA (Sep 16) CVE-2026-76460 Cisco Identity Services Engineにおける特権APIの不適切な使用に関する脆弱性 CVE-2026-87886 Acr

    @foxbook

    17 Sept 2026

    247 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに1件と2件の脆弱性を追加。 - CVE-2026-58704 (Google Pixel) - CVE-2026-76460 (Cisco ISE) - CVE-2026-87886 (Acronis Backup) 対処期限は3日後の

    @__kokumoto

    16 Sept 2026

    913 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🚨 CVE-2026-76460 — CRITICAL — actively exploited per CISA KEV Cisco Identity Services Engine CVSS 10.0 #Cisco #CVE https://t.co/i0Ipnvm8Du

    @threatpodium

    16 Sept 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🛡️ We added Cisco Identity Services Engine vulnerability CVE-2026-76460 & Acronis Backup vulnerability CVE-2026-87886 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/fmm

    @CISACyber

    16 Sept 2026

    8713 Impressions

    11 Retweets

    39 Likes

    9 Bookmarks

    0 Replies

    0 Quotes

Configurations