CVE-2026-76460

● KEV CRITICAL

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authenticati...

Affects 0 products across 1 vendor.

CVSS 3.110.0
EPSS14.0%
Percentile96th
PatchUnknown
KEV Added2026-09-16
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-648: CWE-648
Related Attack Patterns (CAPEC)
CAPEC-107 Cross Site Tracing
via CWE-648
CAPEC-234 Hijacking a privileged process
via CWE-648

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical severity vulnerability (CVE-2026-76460) affects the target system. A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could expl...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-76460?
A critical severity vulnerability (CVE-2026-76460) affects the target system. A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could expl...
What is the CVSS score for CVE-2026-76460?
CVE-2026-76460 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 14.0%.
Is CVE-2026-76460 actively exploited?
Yes. CVE-2026-76460 is in the CISA KEV catalog (added 2026-09-16). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-76460?
Apply vendor patches for CVE-2026-76460. Monitor Cisco advisories.
What systems are affected by CVE-2026-76460?
CVE-2026-76460 affects: Cisco.
Vulnerability Details
CVE IDCVE-2026-76460
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-09-16
Last Modified2026-09-25
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Cisco — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 11 Days
CISA KEV● Active Exploitation Confirmed (added 2026-09-16)
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Cisco
CVE-2007-1257 10.0 The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 76... CVE-2009-1167 10.0 Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6... CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2011-2738 10.0 Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before ...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-76460 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →