Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2916+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Cisco Zero-Day Highlights API Endpoint Authentication Issues
Cisco Zero-Day Highlights API Endpoint Authentication Issues
NEWS

Cisco Zero-Day Highlights API Endpoint Authentication Issues

CVE-2026-76460, a maximum-severity CVSS 10.0 auth bypass in Cisco ISE, is under active exploitation and now sits in CISA's KEV catalog.

Dylan H.

News Desk

September 19, 2026
3 min read

A Gateway Endpoint With No Authentication Check

Cisco has patched an actively exploited zero-day in its Identity Services Engine (ISE), the network access control platform enterprises use to enforce who and what can connect to their network. Tracked as CVE-2026-76460, the flaw carries a maximum CVSS score of 10.0 and allows a remote, unauthenticated attacker to bypass authentication entirely via a crafted request to an API endpoint.

Both Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected, regardless of device configuration. From ISE release 3.1 onward, the Monitoring APIs, External RESTful Services (ERS) APIs, and Open APIs all route through Cisco's Kong API Gateway — and the bug is a missing authentication check on a specific endpoint sitting behind that gateway. Because every one of those API surfaces funnels through the same gateway, a bypass there effectively compromises the whole deployment: an attacker can gain unauthorized administrative access to the appliance, with the potential for complete loss of network visibility, credential theft, or manipulation of authentication policy across the entire enterprise.


Active Exploitation and Federal Deadline

Cisco has confirmed it is "aware of active exploitation of this vulnerability," though it has not disclosed details on the attackers or the nature of the observed activity. CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026, requiring U.S. federal civilian agencies to apply patches by September 19, 2026.

The disclosure lands just days after Cisco confirmed active exploitation of a separate critical flaw, CVE-2026-76461 (CVSS 9.8), in AsyncOS Software for Cisco Secure Email Gateway. Cisco's broader security review that produced this fix also uncovered 21 additional critical vulnerabilities across ISE/ISE-PIC, along with further flaws in its Secure Firewall line.


Remediation

There is no full workaround for CVE-2026-76460. Cisco states that infrastructure access control lists (iACLs) restricting traffic to the affected device can reduce remote exploitation risk, but the only real fix is upgrading to a patched release:

TrackFixed Version
ISE / ISE-PIC 3.5Patch 4
ISE / ISE-PIC 3.4Patch 7
ISE / ISE-PIC 3.3Patch 12
ISE / ISE-PIC 3.2Patch 11
ISE / ISE-PIC 3.1Patch 12

If compromise is suspected, Cisco recommends checking the access.log file on the device for suspicious usernames, and — because the exploit grants root-level access that allows attackers to delete logs to cover their tracks — also inspecting upstream network and firewall logs for unauthorized file uploads or downloads. In confirmed-compromise cases, Cisco's guidance is to re-image affected nodes and restore from a known-good configuration backup rather than trust in-place remediation.

Sources

  • Dark Reading — Cisco Zero-Day Highlights API Endpoint Authentication Issues
  • The Hacker News — Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
  • SecurityWeek — Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
#Zero-Day#CVE#Cisco#Authentication Bypass

Related Articles

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns of an actively exploited CVSS 10.0 auth bypass in ISE (CVE-2026-76460); CISA added it to KEV with a Sep 19 deadline.

4 min read

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Cisco patches CVE-2026-76460, a CVSS 10.0 ISE auth bypass exploited in the wild; CISA gives federal agencies until Sept. 19 to patch.

6 min read

CISA Issues Emergency Directive as Cisco SD-WAN Zero-Day

A maximum-severity authentication bypass in Cisco Catalyst SD-WAN (CVE-2026-20127, CVSS 10.0) has been actively exploited by threat actor UAT-8616 since...

4 min read
Back to all News