Cisco Zero-Day Highlights API Endpoint Authentication Issues

Used in attacksCriticalCVSS 10.0Dark Reading · Rob Wright·

At a glance

Severity
CriticalCVSS 10.0
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-76460
Vendors and products
Cisco
Reported by
1 outlet

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Vulnerabilities referenced

  • CVE-2026-7646010.0Critical

    Cisco Identity Services Engine

    Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

    Used in attacks

    Added to CISA's list 2026-09-16 · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Dark ReadingEstablished SourceFirst reported

    2026-09-18 19:26 UTC

Related stories