CVE Tools
Back to feed
Exploited in the wild Identity Services Engine (ISE) zero-day ISE Passive Identity Connector (ISE-PIC) Cisco auth-bypass

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Cisco says CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), is being exploited in the wild. A crafted request to an affected API can let an unauthenticated remote attacker bypass the web management interface and potentially obtain root-level command execution. Update to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4; Cisco reports no workaround.