Between September 17 and 18, 2026, Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC API endpoints that allows unauthenticated attackers to gain root access and execute arbitrary commands. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog due to active exploitation in the wild.
13 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. # CiscoIse # AuthBypass # CisaKev https:// cyberworldops.eu/en/cisco-ise- api-authentication-flaw-opens-a-remote-path-to-root-access
🚨 Cisco ISE CVE-2026-76460 is being actively exploited. A CVSS 10.0 authentication bypass lets unauthenticated remote attackers send a crafted API request and gain unauthorized access to Cisco ISE/ISE-PIC. Cisco warns successful exploitation can lead to root-level command execution, while attackers may be able to erase evidence of compromise. 🔎 Hunt ISE Kong access logs for suspicious usernames.
🤖 CVE-2026-76460: max-severity auth bypass in the Cisco ISE/ISE-PIC API, actively exploited in the wild. Allows arbitrary file upload/download and root command execution. Added to CISA KEV with a 3-day patch deadline for federal agencies. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/ # CVE # InfoSec # CyberSec
🔹 SecurityWeek Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek. 🔗 https://www. securityweek.com/active-exploi tation-triggers-emergency-patch-for-cisco-ise-zer
CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: https:// radar.offseq.com/threat/cisco- warns-of-max-severity-ise-zero-day-exploited-in-attacks-7c00b7de95d29289 # OffSeq # Cisco # ZeroDay # Vuln # Cybersecurity
🔴 New security advisory: CVE-2026-76460 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-76460-cisco-ise-auth-bypass-exploited-in-wild by Yazoul AI # InfoSec # Security
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day https://www. securityweek.com/active-exploi tation-triggers-emergency-patch-for-cisco-ise-zero-day/
⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls. https:// threatnoir.com/focus # info
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API… #hackernews #news Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirm
Cisco ISE zero-day CVE-2026-76460 is being actively exploited. The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges. Cisco says there is no complete workaround and recommends upgrading immediately. Read more here: https:// forum.hashpwn.net/post/16740 # Cisco # CVE # CyberSecurity # InfoSec # hashpwn
🔹 darkreading Cisco Zero-Day Highlights API Endpoint Authentication Issues The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. 🔗 https://www. darkreading.com/vulnerabilitie s-threats/cisco-zero-day-api-endpoint-authentication-issues