Critical Authentication Bypass Vulnerability in Cisco Identity Services Engine (ISE) Under Exploitation
Successful exploitation of CVE-2026-76460 could allow a remote attacker to bypass authentication by sending a crafted request to an affected API endpoint
Summary
Successful exploitation of CVE-2026-76460 could allow a remote attacker to bypass authentication by sending a crafted request to an affected API endpoint
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-76460
Cisco has stated that it is aware of active exploitation of CVE-2026-76460 in the wild.
The NHS England National CSOC assesses further exploitation as highly likely.
Introduction
Cisco has released a security advisory addressing an exploited critical authentication bypass vulnerability affecting Cisco Identity Services Engine (ISE).
- CVE-2026-76460 - Insufficient Authentication Control vulnerability - CVSSv3.1 Score: 10.0
Cisco's Identity Services Engine Hardening Release: September 2026 advisory
Cisco has published a Identity Services Engine Hardening Release: September 2026 advisory following a comprehensive internal security review. The update addresses multiple vulnerability classes including improper neutralisation of special elements in output used by a downstream component, improper access control, incorrect resource transfer between spheres, insufficiently protected credentials, improper input validation, and improper privilege management vulnerabilities.
To streamline disclosure, Cisco grouped vulnerabilities according to their underlying Common Weakness Enumeration (CWE) category and assigned a single CVE identifier to each group. The vulnerability discussed in this Cyber Alert, CVE-2026-76460, is grouped under identifier CVE-2026-20192.
Remediation advice
Affected organisations are encouraged to review the Cisco Identity Services Engine Authentication Bypass Vulnerability and Identity Services Engine Hardening Release: September 2026 advisories and apply relevant updates as soon as possible.
Definitive source of threat updates
Last edited: 17 September 2026 2:01 pm