Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6037 articles · 217808 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-76460KEVEXPLOITED
cis · cisco identity services engine

Cisco Identity Services Engine Authentication Bypass Vulnerability

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Affected Products

VendorProductVersions
ciscisco identity services engine3.1.0 p8, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p11, 3.4.0, 3.5.0

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

Related News (1 articles)

Tier C
VulDB1h ago
CVE-2026-76460 | Cisco Identity Services Engine Software API improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-648
PublishedSep 16, 2026
Trending Score129🔥
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76461EXPKEV
Cisco Secure Email Gateway SQL Injection Vulnerability
Trending: 145
MEDIUMCVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Trending: 64
CRITICALCVE-2026-76440
Cisco Secure Email Gateway Security Hardening Release
Trending: 55
CRITICALCVE-2026-76443
Cisco Secure Email Gateway Security Hardening Release
Trending: 55
CRITICALCVE-2026-20353
Cisco Secure Email Gateway Security Hardening Release
Trending: 55

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Added to CISA KEV
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026
Actively Exploited
Sep 16, 2026