Cyber Resilience
← All news

KEV: CVE-2026-76460 — Cisco Identity Services Engine (Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability)

Our takeCISA added CVE-2026-76460 to KEV: actively exploited auth bypass in Cisco ISE that lets unauthenticated remote attackers reach the management interface. Patch now if you run ISE.
Sources (6)
What this means for you — Security leader:CISA added CVE-2026-76460 to KEV: actively exploited authentication bypass in Cisco ISE that lets unauthenticated remote attackers reach the management interface. Apply the Cisco patch or workaround immediately if you run ISE or ISE-PIC.
What this means for you — Lean IT orgs:Cisco ISE has a confirmed vulnerability that attackers are already exploiting. Update to the latest version or follow Cisco's workaround if your network uses it; most small teams without ISE can ignore this one.
What this means for you — MSP:CVE-2026-76460 is confirmed exploited in the wild per CISA KEV. Check every client running Cisco ISE or ISE-PIC and apply the available patches or mitigations without delay.
What this means for you — Researcher:CISA KEV addition for CVE-2026-76460 confirms active exploitation of an authentication bypass via privileged API misuse in Cisco ISE and ISE-PIC.