DIRAS TAKE
Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a short remediation deadline, and public exploit code exists, so prioritize mitigations or take affected ISE instances offline if they are internet-exposed.
What is CVE-2026-76460?
An unauthenticated, remote attacker can bypass authentication on an API endpoint in Cisco Identity Services Engine (CVE-2026-76460), allowing unauthorized access to the device's web-based management interface. Affected releases include multiple 3.x builds such as 3.1.0 p8, p9, p10; 3.2.0 p7; and several 3.3 and 3.4 patches listed by the vendor. Exploitation requires network access to the vulnerable API endpoint and a crafted request; no prior credentials or user interaction are required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Cisco Identity Services Engine are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Cisco Identity Services Engine Software 3.x | 3.1.0 p8 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p9 | |
| Cisco Identity Services Engine Software 3.x | 3.3 Patch 2 | |
| Cisco Identity Services Engine Software 3.x | 3.3 Patch 1 | |
| Cisco Identity Services Engine Software 3.x | 3.3 Patch 3 | |
| Cisco Identity Services Engine Software 3.x | 3.4.0 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 p7 | |
| Cisco Identity Services Engine Software 3.x | 3.3 Patch 4 | |
| Cisco Identity Services Engine Software 3.x | 3.4 Patch 1 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p10 |
Is CVE-2026-76460 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-16; U.S. federal agencies were required to remediate by 2026-09-19.
How to fix CVE-2026-76460
- Restrict network access to Cisco ISE management and API endpoints (apply firewalls, access control lists, and VPN-only access)
- Apply any vendor mitigations and configuration guidance from Cisco immediately
- Monitor ISE logs and network traffic for suspicious requests targeting API endpoints and signs of compromise
- Isolate or take internet-exposed ISE instances offline until mitigations are applied
Frequently asked questions
Is CVE-2026-76460 being actively exploited?
CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on 2026-09-16 and directed remediation by 2026-09-19 for federal agencies.
Which Cisco Identity Services Engine versions are affected by CVE-2026-76460?
Cisco Identity Services Engine releases affected include multiple 3.x builds listed by the vendor such as 3.1.0 p8, 3.1.0 p9, 3.1.0 p10, 3.2.0 p7, several 3.3 Patch versions, and 3.4.0/3.4 Patch 1 as provided in the vendor's affected list.
Is there a patch for CVE-2026-76460?
No vendor fixed versions are listed in the provided facts; follow Cisco guidance for mitigations and apply vendor updates when they become available.
Does CVE-2026-76460 require authentication?
No—this vulnerability allows an unauthenticated, remote attacker to craft requests to an API endpoint and bypass authentication on Cisco Identity Services Engine.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76460
- cve.org/CVERecord?id=CVE-2026-76460
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026