CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog on 2026-09-16, confirming active exploitation of a maximum-severity authentication bypass in Cisco Identity Services Engine.
What Is It
CVE-2026-76460 is an authentication bypass in an API of Cisco Identity Services Engine (ISE). Per Cisco's advisory, the flaw stems from insufficient authentication control on an API endpoint. An unauthenticated, remote attacker can exploit it by sending a crafted request to the affected endpoint, gaining unauthorized access to the device by bypassing the web-based management interface.
CISA tracks the weakness as CWE-648 (Incorrect Use of Privileged APIs). The CVSS 3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, scope changed, and total impact to confidentiality, integrity, and availability.
Why It Matters
KEV listing confirms active exploitation in the wild. CISA's SSVC assessment is unambiguous: exploitation active, automatable yes, technical impact total. Ransomware campaign use is currently listed as Unknown.
The due date is 2026-09-19; three days after the date added, an unusually compressed window. The KEV entry also flags forensic triage as required, meaning defenders should assume compromise is possible rather than simply patching and moving on.
What's Vulnerable
Two Cisco products are affected:
Cisco Identity Services Engine Software: a wide span of releases, including 3.1.0 p8 through p11; 3.2.0 p7, 3.2 Patch 8 through Patch 10; 3.3 Patch 1 through Patch 11; 3.4.0 and 3.4 Patch 1 through Patch 6; 3.5.0 and 3.5 Patch 1 through Patch 3.
The affected list as published reaches the highest patch levels enumerated for the 3.3, 3.4, and 3.5 trains, so a recently patched deployment should not be assumed to be out of scope. Cisco's advisory is the authoritative source for whether a fixed release exists for a given train; check it against your installed version rather than inferring coverage from patch recency.
Cisco ISE Passive Identity Connector (ISE-PIC): 3.4.0 and 3.5.0.
Patch Status
CISA's required action: apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Consult the Cisco security advisory below for fixed-release details.
Sources
- Cisco Security Advisory; cisco-sa-ISE-ABP-VNSW7Tn5: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- NVD, CVE-2026-76460: https://nvd.nist.gov/vuln/detail/CVE-2026-76460
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460
- CISA BOD 26-04; Prioritizing Security Updates Based on Risk: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements): https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk