Key Facts

Cisco disclosed CVE-2026-76460, an authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco says it is aware of active exploitation.

Technical Details

Cisco states that an unauthenticated, remote attacker could bypass authentication by sending a crafted request to an affected API endpoint. The vendor rates the vulnerability Critical with a CVSS score of 10.0.

Impact & Mitigation

Cisco says successful exploitation could allow an attacker to obtain root privileges. Upgrade to a fixed release listed in the Cisco advisory; Cisco also documents iACL-based access restrictions as a temporary measure where immediate upgrading is not possible.

Sources

By Allan