Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
What happened
Cisco confirmed that unauthenticated attackers are actively exploiting CVE-2026-76460, an authentication bypass vulnerability in an API endpoint of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector. By sending a crafted request to this endpoint, remote attackers can bypass the web-based management interface to gain unauthorized access to affected devices running releases 3.0 through 3.5. Cisco advises customers to upgrade to the latest fixed patches, as no workarounds exist for this flaw.
Why it ranks #1
Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in ISE API endpoints allowing unauthenticated remote access to management interfaces on versions 3.0 through 3.5.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
What to do
Upgrade to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, as no workarounds address this vulnerability.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- product
- Status
- actively exploited