Cisco ISE Authentication Bypass CVE-2026-76460: What Defenders Need to Do Now

Chronological Source Flow
Back

AI Fusion Summary

Cisco disclosed CVE-2026-76460 on September 16, 2026, a maximum-severity authentication bypass affecting Cisco ISE and ISE-PIC. This flaw carries a CVSS score of 10.0, enabling unauthenticated remote attackers to bypass authentication on an API endpoint and gain root privileges on the appliance. Cisco PSIRT confirmed the vulnerability is under active exploitation, which was discovered during a Technical Assistance Center support case. Defenders are urged to patch quickly to prevent unauthorized root access to network access control.
Community Comments
Loading updates...
0