CVE-2026-76460
Cisco Identity Services Engine Authentication Bypass Vulnerability
Description
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
In plain language
AI Act nowCVE-2026-76460 lets someone on the network bypass login to Cisco Identity Services Engine’s web management interface, and it’s already being exploited—so small businesses using this software should act immediately.
CVE-2026-76460 is an authentication bypass in Cisco Identity Services Engine (and related passive identity connector components) where unauthenticated attackers can send crafted network requests to a specific web management/API endpoint to gain unauthorized access.
What to do now
- Check whether you run Cisco Identity Services Engine (or Cisco ISE passive identity connector components) and whether its web management interface is reachable from your network.
- Review your logs immediately for suspicious admin access attempts and activity (especially unusual requests to management endpoints).
- Apply the vendor/security mitigations as soon as possible—there is no fixed version listed in the provided patch information, so follow Cisco guidance for emergency measures.
- If you cannot promptly apply mitigations, remove the device from the network path / restrict access so it is not reachable from untrusted networks (and consider discontinuing use if mitigation isn’t available per CISA guidance).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- Week in review: Cisco patches exploited email gateway 0-day, Revolut breachen-us·Help Net Security·
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)en-us·Help Net Security· Exploited Cisco Identity Services Engine auth-bypass
- Cisco warns of max severity ISE zero-day exploited in attacksen-us·BleepingComputer· Exploited Identity Services Engine (ISE) zero-day
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacksen·The Hacker News· Exploited Identity Services Engine (ISE) zero-day
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Dayen-us·SecurityWeek· Exploited Identity Services Engine (ISE) zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76460 and every CVE in our database. Create a free account — no credit card required.
Create Free Account