Cisco this week disclosed a slew of critical security vulnerabilities impacting its Identity Services Engine (ISE), including a maximum-severity zero-day flaw that’s under exploitation.
CVE-2026-76460 is an authentication bypass vulnerability impacting an API in ISE, Cisco’s network access control and zero-trust solution. According to the company, the flaw stems from “insufficient authentication control” on an ISE API endpoint.
“An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint,” Cisco said in its advisory. “A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.”
The bug was disclosed and patched on Wednesday, and the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on the same day. Cisco also disclosed and patched several other bugs impacting ISE and ISE Passive Identity Connector (ISE-PIC) that have similar API authentication issues.
It’s unclear who is exploiting CVE-2026-76460 and how extensive the activity is. (Dark Reading contacted Cisco for comment, but the company did not respond at press time.) But the zero-day attacks illustrate a trend of API authentication issues for the networking giant, as well as beyond.
“Missing authentication for API endpoints is an industry-wide problem,” Johannes Ullrich, founder of the SANS Internet Storm Center, tells Dark Reading. In theory, each request to an API endpoint should be properly authenticated and access-controlled. However, that doesn’t always happen.
“In some cases, APIs that were not directly reachable in the past are exposed, and in the process, proper authentication and access control are skipped,” Ullrich says. “This easily happens as more extensive APIs are exposed to support more modern web application interfaces.”
ISE Zero-Day Puts Entire Network at Risk
CVE-2026-76460 is particularly dangerous for several reasons. First, successful exploitation allows an attacker to gain root privileges and command execution on vulnerable instances, with no authentication or user interaction required.
Second and more importantly, Ullrich explains, ISE itself is used by other Cisco APIs for authentication and access control. Therefore, an attacker that compromises ISE can disable the solution and gain access to various networks or impersonate other hosts. This could lead to additional compromises, he says, because applications may now rely on access control decisions from the compromised ISE platform.
“In short, it is like replacing a building’s security guard with an imposter, how it allows intruders to enter using fake IDs,” Ullrich says. “Employees inside the building will trust these IDs because they believe that the security guard at the entrance checked them.”
In an advisory for CVE-2026-76460, threat intelligence provider BitSight noted that ISE is at the heart of many organizations’ identity and network access infrastructure. “It helps determine which users and devices can connect to a network and what they can access after connecting,” Emma Stevens, senior threat intelligence advisor at Bitsight, wrote.” Root-level access to that infrastructure can create visibility, integrity, and availability risks across a much wider environment.”
Ullrich notes that API endpoint authentication flaws have been an issue for Cisco, with two similar vulnerabilities disclosed earlier this year. The first, CVE-2026-20223, is an insufficient authentication flaw in the internal REST APIs of Cisco Secure Workload; the vulnerability, which was disclosed in May, also received a maximum 10 out of 10 CVSS score.
The second, CVE-2026-20129, is a critical API authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager with a 9.8 CVSS score. The bug, which was disclosed in February, could allow an attacker to execute commands with the privileges of the netadmin role.
Mitigating CVE-2026-76460 Exploitation
CVE-2026-76460 affects ISE and ISE-PIC, regardless of device configuration. Cisco releases patches for versions 3.1 through 3.5 of ISE and ISE-PIC but noted that version 3.0 is no longer supported and advised customers to upgrade to a fixed version.
Cisco said organizations can partially mitigate the flaw by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic to the affected devices, which would prevent remote exploitation of CVE-2026-76460. However, Cisco cautioned that any mitigations are only temporary solutions and urged customers to move to a fixed version of ISE or ISE-PIC.
Additionally, the company emphasized that successful exploitation of CVE-2026-76460 will give threat actors root privileges for those products, allowing them to delete or conceal evidence of exploitation and indicators of compromise (IoCs).
“Cisco strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity, including but not limited to unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses,” the company stated in the advisory.

Comments are closed