• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-76460: pre-auth authentication bypass in Cisco Identity Services Engine

An unauthenticated, remote attacker can bypass authentication on an API endpoint in Cisco Identity Services Engine (CVE-2026-76460), allowing unauthorized access to the device's web-based management interface. Affected releases include multiple 3.x builds such as 3.1.0 p8, p9, p10; 3.2.0 p7; and several 3.3 and 3.4 patches listed by the vendor. Exploitation requires network access to the vulnerable API endpoint and a crafted request; no prior credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.14026
CWE
CWE-648
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a short remediation deadline, and public exploit code exists, so prioritize mitigations or take affected ISE instances offline if they are internet-exposed.

What is CVE-2026-76460?

An unauthenticated, remote attacker can bypass authentication on an API endpoint in Cisco Identity Services Engine (CVE-2026-76460), allowing unauthorized access to the device's web-based management interface. Affected releases include multiple 3.x builds such as 3.1.0 p8, p9, p10; 3.2.0 p7; and several 3.3 and 3.4 patches listed by the vendor. Exploitation requires network access to the vulnerable API endpoint and a crafted request; no prior credentials or user interaction are required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Cisco Identity Services Engine are affected?

BRANCHAFFECTEDFIXED
Cisco Identity Services Engine Software 3.x3.1.0 p8
Cisco Identity Services Engine Software 3.x3.1.0 p9
Cisco Identity Services Engine Software 3.x3.3 Patch 2
Cisco Identity Services Engine Software 3.x3.3 Patch 1
Cisco Identity Services Engine Software 3.x3.3 Patch 3
Cisco Identity Services Engine Software 3.x3.4.0
Cisco Identity Services Engine Software 3.x3.2.0 p7
Cisco Identity Services Engine Software 3.x3.3 Patch 4
Cisco Identity Services Engine Software 3.x3.4 Patch 1
Cisco Identity Services Engine Software 3.x3.1.0 p10

Is CVE-2026-76460 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-16; U.S. federal agencies were required to remediate by 2026-09-19.

How to fix CVE-2026-76460

  1. Restrict network access to Cisco ISE management and API endpoints (apply firewalls, access control lists, and VPN-only access)
  2. Apply any vendor mitigations and configuration guidance from Cisco immediately
  3. Monitor ISE logs and network traffic for suspicious requests targeting API endpoints and signs of compromise
  4. Isolate or take internet-exposed ISE instances offline until mitigations are applied

Frequently asked questions

Is CVE-2026-76460 being actively exploited?

CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on 2026-09-16 and directed remediation by 2026-09-19 for federal agencies.

Which Cisco Identity Services Engine versions are affected by CVE-2026-76460?

Cisco Identity Services Engine releases affected include multiple 3.x builds listed by the vendor such as 3.1.0 p8, 3.1.0 p9, 3.1.0 p10, 3.2.0 p7, several 3.3 Patch versions, and 3.4.0/3.4 Patch 1 as provided in the vendor's affected list.

Is there a patch for CVE-2026-76460?

No vendor fixed versions are listed in the provided facts; follow Cisco guidance for mitigations and apply vendor updates when they become available.

Does CVE-2026-76460 require authentication?

No—this vulnerability allows an unauthenticated, remote attacker to craft requests to an API endpoint and bypass authentication on Cisco Identity Services Engine.

References