Cisco reports that CVE-2026-76460, an authentication bypass vulnerability in its Identity Services Engine (ISE), is being actively exploited in the wild. The flaw affects a Cisco ISE API endpoint and, according to Cisco, could allow an unauthenticated remote attacker to bypass authentication controls.
Cisco describes the issue as stemming from insufficient authentication controls on the targeted API endpoint. Help Net Security also frames the risk as attackers bypassing ISE’s management interface, linking the bug to ISE’s role in identity-based network access control, device profiling, security posture checks, access policy decisions, and logging.
Both outlets stress that the vulnerability has a maximum severity rating (CVSS 10.0) and that exploitation is ongoing. The primary difference is emphasis: one outlet focuses on Cisco’s security warning and the CVSS scoring, while the other highlights the operational impact as “management interface” bypass activity.