Key Facts
Cisco disclosed CVE-2026-76460, an authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco says it is aware of active exploitation.
Technical Details
Cisco states that an unauthenticated, remote attacker could bypass authentication by sending a crafted request to an affected API endpoint. The vendor rates the vulnerability Critical with a CVSS score of 10.0.
Impact & Mitigation
Cisco says successful exploitation could allow an attacker to obtain root privileges. Upgrade to a fixed release listed in the Cisco advisory; Cisco also documents iACL-based access restrictions as a temporary measure where immediate upgrading is not possible.
