Cisco ISE CVE-2026-76460: critical authentication bypass under active attack

Between September 17 and 18, 2026, Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC API endpoints that allows unauthenticated attackers to gain root access and execute arbitrary commands. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog due to active exploitation in the wild.

13 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA

mastodon:infosec-exchangeother12d ago kagi ↗

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. # CiscoIse # AuthBypass # CisaKev https:// cyberworldops.eu/en/cisco-ise- api-authentication-flaw-opens-a-remote-path-to-root-access

🚨 Cisco ISE CVE-2026-76460 is being actively exploited. A CVSS 10.0 authentication bypass lets unauthenticated remote attackers send a crafted API request and gain unauthorized access to Cisco ISE/IS

mastodon:infosec-exchangeother12d ago kagi ↗

🚨 Cisco ISE CVE-2026-76460 is being actively exploited. A CVSS 10.0 authentication bypass lets unauthenticated remote attackers send a crafted API request and gain unauthorized access to Cisco ISE/ISE-PIC. Cisco warns successful exploitation can lead to root-level command execution, while attackers may be able to erase evidence of compromise. 🔎 Hunt ISE Kong access logs for suspicious usernames.

🤖 CVE-2026-76460: max-severity auth bypass in the Cisco ISE/ISE-PIC API, actively exploited in the wild. Allows arbitrary file upload/download and root command execution. Added to CISA KEV with a 3-d

mastodon:infosec-exchangeother12d ago kagi ↗

🤖 CVE-2026-76460: max-severity auth bypass in the Cisco ISE/ISE-PIC API, actively exploited in the wild. Allows arbitrary file upload/download and root command execution. Added to CISA KEV with a 3-day patch deadline for federal agencies. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/ # CVE # InfoSec # CyberSec

🔹 SecurityWeek Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The p

mastodon:infosec-exchangeother12d ago kagi ↗

🔹 SecurityWeek Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek. 🔗 https://www. securityweek.com/active-exploi tation-triggers-emergency-patch-for-cisco-ise-zer

CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: http

mastodon:infosec-exchangeother12d ago kagi ↗

CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: https:// radar.offseq.com/threat/cisco- warns-of-max-severity-ise-zero-day-exploited-in-attacks-7c00b7de95d29289 # OffSeq # Cisco # ZeroDay # Vuln # Cybersecurity

🔴 New security advisory: CVE-2026-76460 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems •

mastodon:infosec-exchangeother12d ago kagi ↗

🔴 New security advisory: CVE-2026-76460 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-76460-cisco-ise-auth-bypass-exploited-in-wild by Yazoul AI # InfoSec # Security

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authenticatio

mastodon:infosec-exchangeother11d ago kagi ↗

⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls. https:// threatnoir.com/focus # info

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

stream:bsky-jetstreamother11d ago kagi ↗

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API… #hackernews #news Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirm

Cisco ISE zero-day CVE-2026-76460 is being actively exploited. The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privilege

mastodon:infosec-exchangeother11d ago kagi ↗

Cisco ISE zero-day CVE-2026-76460 is being actively exploited. The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges. Cisco says there is no complete workaround and recommends upgrading immediately. Read more here: https:// forum.hashpwn.net/post/16740 # Cisco # CVE # CyberSecurity # InfoSec # hashpwn

🤖 CVE-2026-76460 (CVSS 10.0): authentication bypass in Cisco Identity Services Engine (ISE) API endpoints. Zero-day, maximum severity rating, can let unauthenticated attackers escalate privileges. 🔗

mastodon:infosec-exchangeother11d ago kagi ↗

🤖 CVE-2026-76460 (CVSS 10.0): authentication bypass in Cisco Identity Services Engine (ISE) API endpoints. Zero-day, maximum severity rating, can let unauthenticated attackers escalate privileges. 🔗 https://www. darkreading.com/vulnerabilitie s-threats/cisco-zero-day-api-endpoint-authentication-issues # CVE # 0day # CyberSec

🔹 darkreading Cisco Zero-Day Highlights API Endpoint Authentication Issues The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out o

mastodon:infosec-exchangeother11d ago kagi ↗

🔹 darkreading Cisco Zero-Day Highlights API Endpoint Authentication Issues The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. 🔗 https://www. darkreading.com/vulnerabilitie s-threats/cisco-zero-day-api-endpoint-authentication-issues