Executive Summary

CVE-2026-76460 is an insufficient authentication control on a Cisco Identity Services Engine (ISE) API endpoint that lets an unauthenticated, remote attacker bypass the web-based management interface with a single crafted request. In OT environments where ISE enforces network access policy for the boundary between enterprise IT and the plant floor, a compromised policy engine means the mechanism that decides who reaches your PLCs, RTUs, and engineering workstations can be silently overridden.

Technical Exposure Breakdown

The flaw sits in an API endpoint that fails to enforce authentication before processing requests. According to the grounding data, an attacker sends a crafted request directly to the affected API and gains unauthorized access to the device, bypassing the web-based management interface entirely. The CVSS score is 10.0, and the vulnerability is listed in the known exploited vulnerability catalog, meaning this is being used in the wild, not sitting theoretically.

Cisco ISE and the ISE Passive Identity Connector are both named in the grounding data as affected products. The specific vulnerable version ranges and patch status are not confirmed in the source material, so operators should not assume a particular build is safe or unsafe until vendor advisory data is validated against their own deployment inventory.

The attack vector matters here. This is a network-reachable, pre-authentication defect. There is no credential requirement, no user interaction, and no local access prerequisite. Any host that can reach the ISE API surface is a launch point. In practice that means management VLANs, jump host segments, and any flat network path that was never properly isolated becomes an exposure.

OT Impact and Compliance Risk

ISE is not an ICS component, but in many utility and industrial architectures it is the trust anchor for the electronic security perimeter. It authenticates devices onto the network, enforces posture, and gates access between zones. An attacker who bypasses ISE authentication can potentially alter authorization policy, authorize rogue endpoints, or disable enforcement that currently keeps untrusted hosts out of Level 2 and Level 3 networks. The physical consequence is indirect but severe: the control that prevents an attacker from reaching a Modbus or DNP3 endpoint can be turned off from a single unauthenticated request.

For NERC CIP entities, ISE frequently supports CIP-005 electronic access controls and CIP-007 system security management. A compromise of the policy engine undermines the auditable enforcement those standards require. Under IEC 62443, ISE often implements the zone and conduit access controls central to a segmented architecture, so this defect degrades the foundational control that the entire zoning model depends on. Water and wastewater operators subject to AWIA 2018 risk and resilience obligations, and pipeline operators under TSA SD-02C, should treat any identity and access management component with a KEV-listed pre-auth bypass as a priority finding in their required assessments.

Compensating Controls

Do not rely on a patch alone, and do not run an active vulnerability scan against a production ISE node to confirm exposure. Active scanning of management infrastructure can destabilize the very access control plane you depend on, and aggressive probing near industrial segments can brick fragile downstream components. Use passive asset inventory and configuration review instead.

BreachSpider Intel

BreachSpider tracks KEV-listed identity and access management defects like CVE-2026-76460 and maps them to affected OT architectures so operators can prioritize before exploitation reaches the plant floor.