Cisco ISE Critical Auth Bypass CVE-2026-76460 Actively Exploited, Patches Released
A maximum-severity vulnerability (CVSS 10.0) in Cisco Identity Services Engine, tracked as CVE-2026-76460, was disclosed on September 16, 2026, and is already being actively exploited in the wild. The flaw stems from insufficient authentication controls on an API endpoint, allowing unauthenticated attackers to bypass the web management interface and execute commands with root privileges. Cisco PSIRT discovered the issue while handling a Technical Assistance Center support case, and no temporary workaround exists for affected versions spanning releases 3.1 through 3.5. Successful exploitation grants attackers control over network access policies, enabling them to alter access rules and move laterally into internal networks. Cisco has released targeted patches across all affected release lines, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate remediation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in