Skip to content
skopnix
actively exploited · CISA KEV

CVE-2026-76460

NVD CRITICAL 10 · published 2026-09-16 · 1 on the wire

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Exploited in the wild

Yes

CISA added it 2026-09-16. An observation, not a forecast.

EPSS · 30-day forecast

FIRST has not scored this id yet.

CVSS · NVD

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Internet exposure

No exposure census on this CVE's dispatches.

On the wire1
References
Early access

Watch this one?

Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.

bot-protected