ZeroHour
SOCRadarpublished ()ingested ameer
Part of a story covered by 9 sources: “Cisco Emergency-Patches Actively Exploited CVSS 10.0 Zero-Day CVE-2026-76460 in Identity Services Engine; CISA Adds to KEV” — merged summary and timeline →

CVE-2026-76460: Cisco ISE Flaw Actively Exploited

criticalExploit / PoC exploited in the wildimportance 80CVE-2026-76460
AI summary · glm-5.3-flash

CVE-2026-76460, a critical flaw in Cisco Identity Services Engine and ISE-PIC, is being actively exploited in the wild.

SOCRadar reports that CVE-2026-76460 is a critical security flaw in Cisco's Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The advisory indicates the vulnerability bypasses authentication protections, and the flaw is confirmed to be actively exploited. ISE is widely deployed for enterprise network access control, making exploitation of this bug high-impact for affected organizations.

  • Critical flaw affects Cisco ISE and ISE Passive Identity Connector
  • CVE-2026-76460 reportedly allows an authentication bypass
  • SOCRadar confirms the vulnerability is being actively exploited

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76460
Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC

Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.

Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface.

10.0 KEV PoC
  • Cisco Identity Services Engine (ISE)
  • Cisco ISE Passive Identity Connector (ISE-PIC)
large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces
Full article

CVE-2026-76460: Cisco ISE Flaw Actively Exploited CVE-2026-76460 represents a critical security flaw in Cisco’s Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Because the vulnerability bypas

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.