Cisco confirmed attackers are exploiting CVE-2026-76460, a CVSS 10.0 flaw giving unauthenticated root on Identity Services Engine. ISE decides which devices join the network, so a rooted node hands over every access decision and the device credentials it stores.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Cisco says CVE-2026-76460 is under active exploitation. It scores 10.0, needs no credentials, and puts an unauthenticated attacker past the web management interface of an Identity Services Engine appliance.
Reality
- Evidence45
- Adoption30
- Hype gap−10
- Incentives50
- Confidence48
Cisco's PSIRT says CVE-2026-76460 is being exploited, and the company has published no workaround, so the fix is a branch-specific patch. ISE 3.0 is past End of Software Maintenance and gets a migration.
Publishers:cisco.com · dev.to Reality
- Evidence72
- Adoption42
- Hype gap+6
- Incentives38
- Confidence68
CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.
Perspective Coverage
16 publishers
- Builder
- Builder 18%
- Operator
- Operator 64%
- Investor
- Investor 18%
Reality
- Evidence82
- Adoption58
- Hype gap−8
- Incentives62
- Confidence80
Cisco and CISA confirm CVE-2026-76460 is being exploited in the wild. The flaw sits in the ISE and ISE-PIC management API, scores 10.0, and affects vulnerable releases whatever optional features are turned on.
Reality
- Evidence62
- Adoption52
- Hype gap0
- Incentives30
- Confidence58
Cisco disclosed an unauthenticated authorization bypass in the Identity Services Engine REST API on 16 September. Because the request never presents a credential, it leaves just one trace: a privileged API call that succeeded.
Reality
- Evidence45
- Adoption30
- Hype gap+18
- Incentives52
- Confidence58
The access control vendor now takes risk signals from Microsoft Defender, CrowdStrike and SentinelOne to cut an AI agent's connection mid-session. The pitch rests on numbers it did not gather.
Reality
- Evidence24
- Adoption10
- Hype gap+46
- Incentives84
- Confidence33