๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Summary
Cisco Identity Services Engine (ISE), a system that manages network access and identity verification, has a vulnerability where privileged APIs (sets of functions that grant special access powers) are used incorrectly. This flaw allows an unauthenticated attacker to remotely bypass the web-based management interface and gain unauthorized access to the device. This vulnerability is actively being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations according to Cisco's vendor instructions while following CISA's BOD 26-04 guidance for prioritizing security updates based on risk. Evaluate each affected device's exposure to the internet and ensure compliance with BOD 26-04 patching timelines. If mitigations are unavailable, follow BOD 26-04 guidance for cloud services or discontinue use of the product. Patch deadline: 2026-09-19. See Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5 for specific patch information.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
September 15, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76460
First tracked: September 16, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%