Cisco ISE Hit by Nine Critical Vulnerabilities, Including Unauthenticated Bypasses
Cisco's Identity Services Engine (ISE) has been hit by nine critical vulnerabilities, including two unauthenticated REST API authentication bypasses that carry a CVSS score of 10.0 and are currently under active exploitation.
The Cisco PSIRT advisory confirmed that at least one enterprise environment was already compromised before the vulnerability was identified and reported, highlighting the severity of the issue.
The discovery of CVE-2026-76460 occurred during a Cisco Technical Assistance Center (TAC) support case, demonstrating how vulnerabilities can be exploited in real-world scenarios.