Cisco Warns of Critical Vulnerability in Identity Services Engine
A critical vulnerability in Cisco's Identity Services Engine (ISE) and ISE-Passive Identity Connector (ISE-PIC) puts organizations at risk of unauthorized access to management functions.
The flaw, tracked as CVE-2026-76460, allows remote attackers to bypass normal login requirements by sending specially crafted requests to the vulnerable API endpoint.
Cisco recommends immediate patching because no workaround fully mitigates the vulnerability, which has a maximum CVSS severity score of 10.0.