CVE-2026-76460 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 14% (pctl 96)
Patch first
On CISA KEV — known exploited in the wild, due 2026-09-19.
Description
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 14.03% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-648 |
| On CISA KEV | yes — remediate by 2026-09-19 |
| Public exploit | none known |
| Published | 2026-09-16 |
| Last modified | 2026-09-25 |
CISA KEV
| Name | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability |
|---|---|
| Added | 2026-09-16 |
| Due | 2026-09-19 |
| Vendor / product | Cisco / Identity Services Engine |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| cisco | identity services engine |
| cisco | identity services engine passive identity connector |
References
→ the Explorer · watch your stack · NVD