TTO-2026-0918-137 · September 18, 2026 Zero-DayActive ExploitationCritical

Cisco Identity Services Engine CVE-2026-76460 CVSS 10.0 Zero-Day Exploited — CISA Deadline September 19

cisco.comCVE-2026-76460 CVSS 10.0Unauthenticated API authentication bypassIdentity Services Engine and ISE-PICCisco PSIRT confirms active exploitationCISA KEV Sep 19 deadlineNo workarounds availableSecond Cisco zero-day in two days

Summary

Cisco has released emergency patches for CVE-2026-76460, a maximum-severity zero-day vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that is being actively exploited in the wild. The vulnerability carries a CVSS score of 10.0 and allows an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the affected device by sending a crafted request to a vulnerable API endpoint. Cisco’s Product Security Incident Response Team confirmed active exploitation before the patch was released. No workarounds exist; patching is the only mitigation. CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 17 and set a federal agency deadline of September 19, 2026 to patch or stop using ISE entirely. This is the second actively exploited Cisco zero-day disclosed in as many days, following CVE-2026-76461 in Cisco Secure Email Gateway on September 15.

Timeline

DateEvent
Prior to Sep 17, 2026CVE-2026-76460 exploited in the wild before Cisco disclosure; vulnerability identified while resolving a Cisco TAC support case
Sep 17, 2026Cisco releases emergency patches; Cisco PSIRT confirms active exploitation; no workarounds available
Sep 17, 2026CISA adds CVE-2026-76460 to KEV catalog; sets September 19 federal patch-or-disable deadline

What Happened

CVE-2026-76460 is an authentication bypass vulnerability in an API endpoint of Cisco Identity Services Engine. The API endpoint fails to apply sufficient authentication controls, allowing an unauthenticated remote attacker to send a crafted HTTP request and bypass the web-based management interface to gain unauthorized access to the device. Cisco states the vulnerability affects ISE and ISE-PIC regardless of device configuration.

Cisco ISE is the company’s centralized network access control and identity-based policy platform — the enforcement point for Zero Trust security models that determines who and what is allowed onto a network and what resources they can access. Successful exploitation grants authentication bypass to the ISE management plane. Cisco’s incident response guidance warns that attackers may obtain root-level command execution on the affected system.

Cisco advised administrators to inspect access.log files on every ISE node for suspicious usernames and strongly recommended re-imaging affected nodes and re-entering configuration data if suspicious activity is found. The company has not attributed the active exploitation to a specific threat actor. Cisco ISE has now had three actively exploited vulnerabilities added to the CISA KEV catalog since June 2025.

Domain Intelligence

cisco.com — 61.91

Score unchanged from TTO-2026-0910-112. cisco.com scores in the low-trust range at 61.91. Cisco is the vendor of the affected Identity Services Engine product and the party that disclosed, patched, and published remediation guidance for CVE-2026-76460.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 18, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026