CVE Tools

CVE-2026-76460

Cisco Identity Services Engine Authentication Bypass Vulnerability

Published: Sep 16, 2026Updated: Sep 17, 2026 Sources: CVE List NVDCWE-648

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

In plain language

AI Act now

CVE-2026-76460 lets someone on the network bypass login to Cisco Identity Services Engine’s web management interface, and it’s already being exploited—so small businesses using this software should act immediately.

Executive summary

CVE-2026-76460 is an authentication bypass in Cisco Identity Services Engine (and related passive identity connector components) where unauthenticated attackers can send crafted network requests to a specific web management/API endpoint to gain unauthorized access.

If affected, business impact
Full admin console takeoverSecurity policy changes by attackersUser and access data compromiseService disruption or lockout

What to do now

  1. Check whether you run Cisco Identity Services Engine (or Cisco ISE passive identity connector components) and whether its web management interface is reachable from your network.
  2. Review your logs immediately for suspicious admin access attempts and activity (especially unusual requests to management endpoints).
  3. Apply the vendor/security mitigations as soon as possible—there is no fixed version listed in the provided patch information, so follow Cisco guidance for emergency measures.
  4. If you cannot promptly apply mitigations, remove the device from the network path / restrict access so it is not reachable from untrusted networks (and consider discontinuing use if mitigation isn’t available per CISA guidance).
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Sep 16, 2026
Remediation due:Sep 19, 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

0 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Workaround Available

References

5

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-76460 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows