Skip to main content

Critical Authentication Bypass Vulnerability in Cisco Identity Services Engine (ISE) Under Exploitation

Successful exploitation of CVE-2026-76460 could allow a remote attacker to bypass authentication by sending a crafted request to an affected API endpoint

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-76460 could allow a remote attacker to bypass authentication by sending a crafted request to an affected API endpoint


Threat details

Exploitation of CVE-2026-76460

Cisco has stated that it is aware of active exploitation of CVE-2026-76460 in the wild.

The NHS England National CSOC assesses further exploitation as highly likely.


Introduction

Cisco has released a security advisory addressing an exploited critical authentication bypass vulnerability affecting Cisco Identity Services Engine (ISE).

  • CVE-2026-76460 - Insufficient Authentication Control vulnerability - CVSSv3.1 Score: 10.0

Cisco's Identity Services Engine Hardening Release: September 2026 advisory

Cisco has published a Identity Services Engine Hardening Release: September 2026 advisory following a comprehensive internal security review. The update addresses multiple vulnerability classes including improper neutralisation of special elements in output used by a downstream component, improper access control, incorrect resource transfer between spheres, insufficiently protected credentials, improper input validation, and improper privilege management vulnerabilities.

To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. The vulnerability discussed in this Cyber Alert, CVE-2026-76460, is grouped under identifier CVE-2026-20192.


Remediation advice

Affected organisations are encouraged to review the Cisco Identity Services Engine Authentication Bypass Vulnerability and Identity Services Engine Hardening Release: September 2026 advisories and apply relevant updates as soon as possible.



Last edited: 17 September 2026 2:01 pm