CYBERSECURITYTRACKER
TRACKING6,994 stories in this site build1,470 vulnerability news stories in this site build
Permanent story citation

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7611

As cited

Copy frozen at (site build).

vulnerabilities

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.

Why it matters: Organizations running Cisco ISE must patch immediately, as attackers with network access can bypass authentication to reach identity and network access control systems that determine user permissions and device posture.

VendorsCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.

Why it matters: Organizations running Cisco ISE must patch immediately, as attackers with network access can bypass authentication to reach identity and network access control systems that determine user permissions and device posture.

VendorsCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.

Why it matters: Organizations running Cisco ISE must patch immediately, as attackers with network access can bypass authentication to reach identity and network access control systems that determine user permissions and device posture.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary