Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-76460

Cisco Identity Services Engine Authentication Bypass Vulnerability

Cisco / Cisco Identity Services Engine Software · 3.1.0 p8

Severity
CVSS 10.0 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-76460 is an unauthenticated Cisco Identity Services Engine Authentication Bypass Vulnerability. A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Cisco / Cisco Identity Services Engine Software 3.1.0 p8.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

Cisco Identity Services Engine Authentication Bypass Vulnerability

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint.

An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Cisco Affected
Cisco Identity Services Engine Software
3.1.0 p8 3.1.0 p9 3.3 Patch 2 3.3 Patch 1 3.3 Patch 3 3.4.0 3.2.0 p7 3.3 Patch 4 3.4 Patch 1 3.1.0 p10 3.3 Patch 5 3.3 Patch 6 3.4 Patch 2 3.3 Patch 7 3.4 Patch 3 3.5.0 3.4 Patch 4 3.3 Patch 8 3.2 Patch 8 3.5 Patch 1 3.3 Patch 9 3.2 Patch 9 3.4 Patch 5 3.5 Patch 3 3.5 Patch 2 3.3 Patch 10 3.3 Patch 11 3.4 Patch 6 3.2 Patch 10 3.1.0 p11
Cisco Affected
Cisco ISE Passive Identity Connector
3.4.0 3.5.0
Published
16 Sep 2026
Exploitation Reported
16 Sep 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

edge cisa

CVE References

  • CVE Record CVE.org · CVE Record https://www.cve.org/CVERecord?id=CVE-2026-76460
  • cisco-sa-ISE-ABP-VNSW7Tn5 sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Cisco Security Advisory

Recorded 16 Sep 2026

A trusted third party reported exploitation.

Proof of concept available

GitHub

Recorded 17 Sep 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Cisco Security Advisory First 2026-09-16 19:21 UTC
CISA 2026-09-16 19:30 UTC
CVE 2026-09-16 20:50 UTC
TheHackerNews 2026-09-17 06:39 UTC
TheRegister 2026-09-17 12:40 UTC
Qualys ThreatPROTECT 2026-09-17 13:46 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

10.0 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

Recent mention · Qualys ThreatPROTECT

CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)

Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to bypass authentication. Cisco mentioned in...

Read full advisory

All Mentions

Recent mention · Qualys ThreatPROTECT

CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)

Qualys ThreatPROTECT · 17 Sep 2026

Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to bypass authentication. Cisco mentioned in their advisory that they are aware of active exploitation of this vulnerability. CISA acknowledged the active exploitation of the vulnerability by adding to its … Continue reading "CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)"

Recent mention · TheRegister

Cisco drops another exploited zero-day, this time a perfect 10

TheRegister · 17 Sep 2026

ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch

Recent mention · NCSC Security Advisories

NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

NCSC Security Advisories · 17 Sep 2026

Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek aangemerkt. Op basis van de door Cisco gepubliceerde CVSS-scores kunnen vier kwetsbaarheden zonder...

Recent mention · TheHackerNews

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

TheHackerNews · 17 Sep 2026

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

Recent mention · Cisco Security Advisory

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Cisco Security Advisory · 16 Sep 2026

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables.  To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Cisco Identity Services Engine Title CVE ID SIR Base Score Cisco Identity Services Engine Hardening...

Recent mention · Cisco Security Advisory

Cisco Identity Services Engine Authentication Bypass Vulnerability

Cisco Security Advisory · 16 Sep 2026

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released software updates that address this vulnerability. There are no workarounds that address this...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

S3v3n-JG/CVE-2026-76460

github · Created 2026-09-17 12:00:16 UTC · 1 stars · AI assessment 85%

CVE-2026-76460

Timeline

From disclosure to observed exploitation

  1. 13:46 UTC

    KEV confirmed by Qualys ThreatPROTECT

    Exploitation attested by an external source

  2. 12:40 UTC

    KEV confirmed by TheRegister

    Exploitation attested by an external source

  3. 12:00 UTC

    Public PoC available

    Public proof-of-concept code published

  4. 06:39 UTC

    KEV confirmed by TheHackerNews

    Exploitation attested by an external source

  5. 20:50 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  6. 20:12 UTC

    CVE published

    Vulnerability disclosed publicly

  7. 19:30 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  8. 19:21 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  9. 12:02 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-76460

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-76460",
  "confidence": "Confirmed",
  "cvss_score": 10.0,
  "cvss_estimated": false,
  "epss_score": null,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}