Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-76423
cis · cisco identity services engine

Cisco ISE API Authentication Bypass Vulnerability

Description

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.

Affected Products

VendorProductVersions
ciscisco identity services engine3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p72, 3.1.0 p11, 3.3 Patch 12, 3.2.0, 3.1.0, 3.3.0, 3.4.0, 3.5.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco secure firewall management centercert_advisory90%
cisidentity services engine (ise)cert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ

Related News (7 articles)

Tier B
CERT-FR7d ago
Bulletin d'actualité CERTFR-2026-ACT-040 (21 septembre 2026)
→ No new info (linked only)
Tier B
CCCS Canada10d ago
AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460
→ No new info (linked only)
Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco ISE und ISE-PIC: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco Secure Firewall Management Center: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security10d ago
Jetzt patchen! Angreifer knipsen Firewalls von Cisco aus
→ No new info (linked only)
Tier B
CERT-FR11d ago
Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-76423 | Cisco Identity Services Engine REST API improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
CWECWE-290
PublishedSep 16, 2026
Trending Score30
Source articles7
Independent5
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76460EXPKEV
Cisco Identity Services Engine Authentication Bypass Vulnerability
Trending: 104
CRITICALCVE-2026-76461EXPKEV
Cisco Secure Email Gateway SQL Injection Vulnerability
Trending: 60
MEDIUMCVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Trending: 45
CRITICALCVE-2026-76440
Cisco Secure Email Gateway Security Hardening Release
Trending: 28
CRITICALCVE-2026-20353
Cisco Secure Email Gateway Security Hardening Release
Trending: 28

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026