## Overview
CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) list on September 16, 2026. This vulnerability affects Cisco Identity Services Engine (ISE) and allows unauthenticated, remote attackers to bypass authentication. The addition to the KEV list indicates a federal deadline for remediation.
## Technical Details
The vulnerability stems from insufficient authentication control on an API endpoint within Cisco ISE. Attackers can exploit this by sending crafted requests to the affected API. If successful, they gain unauthorized access to the device, bypassing the web-based management interface entirely. Evidence of exploitation has prompted CISA's action.
## Impact
Exploitation of CVE-2026-76460 can lead to unauthorized access to sensitive systems managed by Cisco ISE. This could allow attackers to manipulate configurations, access sensitive data, or launch further attacks within the network. Given the CVSS score of 10.0, the risk is critical.
## Mitigation
Defenders should immediately apply available patches from Cisco. Regularly audit API access controls and ensure strong authentication measures are in place. Monitor network traffic for unusual API requests that may indicate an attempted exploit. Organizations should prioritize this vulnerability due to its high risk and potential impact.
CSURFACE Threat Sensor