Cisco ISE Critical Auth Bypass CVE-2026-76460 Actively Exploited, Patch Urged
Cisco disclosed on September 16, 2026, that a maximum-severity authentication bypass vulnerability, CVE-2026-76460, in its Identity Services Engine (ISE) and ISE-PIC is being actively exploited in the wild. The flaw carries a CVSS score of 10.0 and allows an unauthenticated remote attacker to bypass API authentication and gain root privileges on the affected appliance. Cisco's PSIRT discovered the vulnerability while handling a Technical Assistance Center support case, indicating real-world exploitation rather than theoretical research. The bug affects ISE versions 3.1 through 3.5, and no temporary workaround has been made available, increasing urgency for organizations to patch immediately. Cisco has released targeted fixes across all affected branches, and administrators are strongly advised to apply the appropriate patch given confirmed active exploitation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in