CVE-2026-76460
CVE-2026-76460 is a critical-severity vulnerability in Cisco Identity Services Engine with a CVSS 3.x base score of 10.0. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-09-16). The underlying weakness is classified as CWE-648.
Key facts
- Severity: Critical (CVSS 3.x base score 10.0)
- EPSS exploit prediction: 1% (54th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2026-09-16)
- Weakness: CWE-648
- Affected product: Cisco Identity Services Engine
- Published:
- Last modified:
Description
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Frequently asked questions
- What is CVE-2026-76460?
- A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- How severe is CVE-2026-76460?
- CVE-2026-76460 has a CVSS 3.x base score of 10.0, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-76460 being actively exploited?
- Yes. CVE-2026-76460 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-09-16, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2026-76460?
- CVE-2026-76460 primarily affects Cisco Identity Services Engine. In total, 92 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-76460?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- When was CVE-2026-76460 published?
- CVE-2026-76460 was published on 2026-09-16 and last updated on 2026-09-17.
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460
Affected products (92)
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch10:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch11:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch9:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch10:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch7:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch8:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch9:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch10:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch11:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch7:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch8:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch9:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:*
More vulnerabilities in Cisco Identity Services Engine
- CVE-2025-20337 — Critical (CVSS 10.0): A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to…
- CVE-2025-20282 — Critical (CVSS 10.0): A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to…
- CVE-2025-20281 — Critical (CVSS 10.0): A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to…
- CVE-2021-44228 — Critical (CVSS 10.0): Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in…
- CVE-2011-3290 — Critical (CVSS 10.0): Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote…
- CVE-2026-20186 — Critical (CVSS 9.9): A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute…
All CVEs affecting Cisco Identity Services Engine →
Other CWE-648 vulnerabilities
- CVE-2026-41329 — Critical (CVSS 9.9): OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via…
- CVE-2024-8785 — Critical (CVSS 9.8): In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to…
- CVE-2024-11068 — Critical (CVSS 9.8): The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote…
- CVE-2023-4972 — Critical (CVSS 9.8): Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This…
- CVE-2026-41225 — Critical (CVSS 9.1): A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager…
- CVE-2026-41386 — Critical (CVSS 9.1): OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to…