HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Authentication Bypass (CVE‑2026‑76460) in Cisco Identity Services Engine Scores 10.0 CVSS

Cisco's Identity Services Engine (ISE) suffers a zero‑day authentication bypass (CVE‑2026‑76460) that grants unauthenticated access to API endpoints. The flaw’s perfect CVSS rating underscores the urgency for organizations to prove robust access‑control evidence in audits and partner reviews.

Verisq™ Intelligence · 📅 September 19, 2026 · 📰 darkreading.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
darkreading.com

Critical Authentication Bypass (CVE‑2026‑76460) in Cisco Identity Services Engine (ISE)

What It Is — Cisco ISE contains an authentication bypass flaw (CVE‑2026‑76460) that allows unauthenticated access to API endpoints. The vulnerability receives a perfect 10.0 CVSS score.

Exploitability — The flaw is a zero‑day; proof‑of‑concept code has been published and active exploitation is being tracked.

Affected Products — Cisco Identity Services Engine (ISE) versions prior to the vendor‑issued patch.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous verification that authentication controls are correctly configured across API surfaces.
  • Provides a concrete test case for the “access control” control objective that underpins many frameworks (e.g., NIST CSF).
  • Failure to remediate leaves audit evidence incomplete, weakening the defensible posture enterprises must show to regulators and partners.

Recommended Actions

  1. Apply Cisco’s emergency patch for CVE‑2026‑76460 immediately.
  2. Conduct a focused review of all ISE API authentication settings and enforce least‑privilege principles.
  3. Capture configuration snapshots and patch‑status logs as audit evidence.
  4. Integrate automated monitoring to alert on any deviation from the approved authentication baseline.

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →