A Critical Zero-Day Flaw in Cisco’s Identity Services Engine Exposes Networks to Unprecedented Risk
A devastating zero-day vulnerability has been discovered in Cisco’s Identity Services Engine (ISE), a network access control and zero-trust solution used by organizations worldwide. The flaw, designated as CVE-2026-76460, allows attackers to bypass authentication controls and gain root privileges on vulnerable instances with no user interaction required. This critical bug was disclosed and patched by Cisco on Wednesday, but its maximum 10 out of 10 CVSS score indicates the severity of the threat.
The vulnerability affects an API endpoint in ISE, allowing a malicious actor to send a crafted request that would otherwise require proper authentication and access control. According to Cisco’s advisory, successful exploitation could grant the attacker unauthorized access to the affected device by bypassing the web-based management interface. What’s more alarming is that this flaw can be used to compromise not only the ISE system but also other Cisco APIs that rely on it for authentication and access control.
The impact of CVE-2026-76460 cannot be overstated, as ISE is a critical component in many organizations’ identity and network access infrastructure. As threat intelligence provider BitSight noted, root-level access to this infrastructure can create visibility, integrity, and availability risks across the entire environment. In other words, if an attacker gains control of ISE, they can potentially compromise multiple networks and impersonate hosts, leading to further breaches.
Johannes Ullrich, founder of the SANS Internet Storm Center, attributes the vulnerability to a common issue in the industry: missing authentication for API endpoints. “In some cases, APIs that were not directly reachable in the past are exposed, and proper authentication and access control are skipped,” he explains. This is particularly problematic as more extensive APIs are exposed to support modern web application interfaces.
The discovery of CVE-2026-76460 marks a concerning trend in Cisco’s API authentication issues. Earlier this year, two similar vulnerabilities were disclosed: CVE-2026-20223, an insufficient authentication flaw in the internal REST APIs of Cisco Secure Workload, and CVE-2026-20129, a critical API authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager.
The takeaway from this incident is clear: organizations relying on ISE must ensure they have applied the patch for CVE-2026-76460 as soon as possible. Moreover, it’s essential to review and strengthen API endpoint authentication controls to prevent similar vulnerabilities in the future. By being proactive and vigilant, organizations can mitigate the risks associated with these types of flaws and maintain a secure network infrastructure.
Source: Dark Reading — 2026-09-18