CRITICAL

CVE-2026-76460

Cisco Identity Services Engine 2026-09-16 CVSS v3.1
CVSS
10
KEV

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.

This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Weakness (CWE)

CWE-648

EPSS Score

0.78%
Probability of exploitation in next 30 days
54.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE