CVE-2026-76460: Critical Cisco ISE Vulnerability Already Being Actively Exploited
Cisco has patched a critical security vulnerability in its Identity Services Engine (ISE) that is already being actively exploited. Attackers can gain root privileges without credentials, according to NetworkWorld.
The vulnerability, CVE-2026-76460, is located in an API endpoint used for managing ISE and allows attackers to bypass the normal authentication process via the web interface.
Cisco ISE is deployed within corporate networks to determine which users and devices are granted access to network resources. The company has released patches for various supported versions of ISE, including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
This is not the only vulnerability addressed by Cisco this week. The company has also patched 21 critical vulnerabilities in total, including remote code execution vulnerabilities and API leaks. Additionally, three vulnerabilities with a high severity rating and eighteen with a medium severity rating were addressed.