Exploited in the wild Identity Services Engine (ISE) zero-day ISE Passive Identity Connector (ISE-PIC) Cisco auth-bypass
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
CVE Tools coverage
Cisco has issued emergency fixes for CVE-2026-76460, a CVSS 10/10 authentication bypass in an API endpoint affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which is being exploited in the wild. Crafted API requests can bypass the web management interface, potentially grant device access and permit root-level command execution; organizations should upgrade to ISE or ISE-PIC versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12 and investigate affected nodes for compromise.