Search/CVE-2026-76460
CVE — Critical

CVE-2026-76460

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVSS v3.1
10 CRITICAL
EPSS
%
probability of exploitation in 30 days
CISA KEV
Listed
confirmed active exploitation
News coverage
7
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Connections
11 relationships
Timeline
disclosure → media coverage
Sep 16, 2026
Disclosure — published as a CVE record.
Sep 17, 2026
securityweek.com reports: Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Sep 17, 2026
thehackernews.com reports: Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Sep 17, 2026
bleepingcomputer.com reports: Cisco warns of max severity ISE zero-day exploited in attacks
Sep 17, 2026
advisories.ncsc.nl reports: NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)
Sep 17, 2026
acn.gov.it reports: Risolte vulnerabilità in prodotti Cisco
Sep 17, 2026
helpnetsecurity.com reports: Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Sep 17, 2026
theregister.com reports: Cisco drops another exploited zero-day, this time a perfect 10