Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-76460

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.

cat cve-2026-76460.json
Vendor
Cisco
Product
Identity Services Engine
CVSS
10.0
EPSS (exploit probability)
14.0%
Status
kev
CISA patch-by (BOD 22-01)
Published

CVE-2026-76460 is a CVSS 10.0 (critical) authentication bypass affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) across all supported release branches (3.1 through 3.5).

The flaw is an incorrect use of privileged APIs on an API endpoint in the web-based management interface. An unauthenticated, remote attacker can send crafted requests to that endpoint to bypass authentication, gain access to the management interface, and achieve root-level command execution on the affected device. Cisco’s advisory notes that successful exploitation can allow an attacker to hide or delete forensic indicators of compromise on the device.

Affected versions: ISE and ISE-PIC 3.1, 3.2, 3.3, 3.4, and 3.5 before the patched releases below.

Patches:

  • ISE/ISE-PIC 3.5: Patch 4
  • ISE/ISE-PIC 3.4: Patch 7
  • ISE/ISE-PIC 3.3: Patch 12
  • ISE/ISE-PIC 3.2: Patch 11
  • ISE/ISE-PIC 3.1: Patch 12

No workarounds are available. Cisco recommends re-imaging any node suspected of compromise rather than attempting forensic cleanup.

CISA added this CVE to the Known Exploited Vulnerabilities catalog on September 16, 2026, with a remediation deadline of September 19, 2026 for federal civilian agencies under BOD 26-04.

Sources: NVD | CISA KEV catalog