Critical Vulnerability Exposed in Cisco’s Identity Services Engine, Putting Networks at Risk
A newly disclosed zero-day vulnerability in Cisco’s Identity Services Engine (ISE) has highlighted a worrying trend of authentication issues affecting API endpoints across various industries. The flaw, identified as CVE-2026-76460, allows attackers to bypass authentication controls and gain unauthorized access to affected devices. This critical security weakness has been added to the US government’s Known Exploited Vulnerabilities catalog and patched by Cisco.
The vulnerability stems from “insufficient authentication control” on an ISE API endpoint, which can be exploited by sending a crafted request to the affected interface. A successful attack could grant an attacker root privileges and command execution on vulnerable instances, with no need for user interaction or authentication. What’s more alarming is that ISE itself is used by other Cisco APIs for authentication and access control, making it a prime target for attackers.
According to Johannes Ullrich, founder of the SANS Internet Storm Center, API endpoint authentication issues are not unique to Cisco. “Missing authentication for API endpoints is an industry-wide problem,” he notes. In some cases, APIs that were previously inaccessible are exposed, and proper authentication and access control are overlooked in the process.
This trend of authentication flaws has been observed before, with two similar vulnerabilities disclosed by Cisco earlier this year. Both CVE-2026-20223 and CVE-2026-20129 received maximum or near-maximum CVSS scores, underscoring the severity of these issues. The ISE zero-day attack is particularly concerning due to its potential to disable entire networks and enable additional compromises.
ISE is a critical component in many organizations’ identity and network access infrastructure, helping determine which users and devices can connect to a network and what they can access after connecting. Root-level access to this infrastructure poses significant risks across a wider environment, compromising visibility, integrity, and availability.
It’s essential for organizations relying on ISE or similar solutions to take immediate action. This includes applying the available patch, re-evaluating their API endpoint authentication controls, and implementing additional security measures to prevent similar attacks in the future. As Ullrich aptly puts it, “Replacing a building’s security guard with an imposter” is exactly what attackers can do when exploiting such vulnerabilities – allowing intruders to enter using fake IDs, which employees trust because they believe the security guard checked them.
In light of this critical vulnerability, organizations should prioritize reviewing and tightening their API endpoint authentication controls to prevent similar attacks. This includes ensuring that all requests are properly authenticated and access-controlled, as well as regularly monitoring for suspicious activity.
Source: Dark Reading — 2026-09-18