Our takeCISA added CVE-2026-76460 to KEV: actively exploited auth bypass in Cisco ISE that lets unauthenticated remote attackers reach the management interface. Patch now if you run ISE.Cyber Resilience desk
Sources (6)
What this means for you — Security leader:CISA added CVE-2026-76460 to KEV: actively exploited authentication bypass in Cisco ISE that lets unauthenticated remote attackers reach the management interface. Apply the Cisco patch or workaround immediately if you run ISE or ISE-PIC.
What this means for you — Lean IT orgs:Cisco ISE has a confirmed vulnerability that attackers are already exploiting. Update to the latest version or follow Cisco's workaround if your network uses it; most small teams without ISE can ignore this one.
What this means for you — MSP:CVE-2026-76460 is confirmed exploited in the wild per CISA KEV. Check every client running Cisco ISE or ISE-PIC and apply the available patches or mitigations without delay.
What this means for you — Researcher:CISA KEV addition for CVE-2026-76460 confirms active exploitation of an authentication bypass via privileged API misuse in Cisco ISE and ISE-PIC.