Cisco ISE Management Interface Hacked with CVSS 10.0 Authentication Bypass
Cisco ISE Auth Bypass CVE-2026-76460 Hits CVSS 10.0 as Federal Deadline Expires
The Cisco Identity Services Engine (ISE) management interface has been hit with a critical vulnerability, assigned a CVSS score of 10.0. The flaw, categorized as CWE-648, arises from the incorrect use of privileged APIs.
An unauthenticated remote attacker can transmit a crafted request to a specific API endpoint that lacks sufficient authentication controls. Successful exploitation grants the attacker command execution with root privileges on the affected system.
The vulnerability impacts Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) releases 3.0 through 3.5, according to the Cisco advisory cisco-sa-ISE-ABP-VNSW7Tn5.