As cited
Copy frozen at (site build).
vulnerabilities
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.
Why it matters: Organizations running Cisco ISE must patch immediately, as attackers with network access can bypass authentication to reach identity and network access control systems that determine user permissions and device posture.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.
Why it matters: Organizations running Cisco ISE must patch immediately, as attackers with network access can bypass authentication to reach identity and network access control systems that determine user permissions and device posture.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.
Why it matters: Organizations running Cisco ISE must patch immediately, as attackers with network access can bypass authentication to reach identity and network access control systems that determine user permissions and device posture.
- Source published
- First seen by Cybersecurity Tracker