CVE-2026-76460
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authenticati...
Affects 0 products across 1 vendor.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical severity vulnerability (CVE-2026-76460) affects the target system. A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could expl...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-76460?
What is the CVSS score for CVE-2026-76460?
Is CVE-2026-76460 actively exploited?
How do I remediate CVE-2026-76460?
What systems are affected by CVE-2026-76460?
| CVE ID | CVE-2026-76460 |
|---|---|
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-09-16 |
| Last Modified | 2026-09-25 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Source | NVD |
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | ● Active Exploitation Confirmed (added 2026-09-16) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
This Vulnerability Is Being Actively Exploited
CVE-2026-76460 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.
Create a free account →