Cisco Zero-Day Highlights API Endpoint Authentication Issues
At a glance
- Severity
- CriticalCVSS 10.0
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-76460
- Vendors and products
- Cisco
- Reported by
- 1 outlet
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Vulnerabilities referenced
- CVE-2026-7646010.0Critical
Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Used in attacksAdded to CISA's list 2026-09-16 · Patch or advisory available
Full record →
Coverage
One outlet has carried this so far.
2026-09-18 19:26 UTC
Related stories
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
The Hacker News · 2026-09-19
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The Hacker News · 2026-09-19
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
The Hacker News · 2026-09-18
- [Control systems] ABB security advisory (AV26-942)
Canadian Centre for Cyber Security · 2026-09-18
- SolarWinds security advisory (AV26-941)
Canadian Centre for Cyber Security · 2026-09-18