Cisco has recently disclosed several critical security vulnerabilities in its Identity Services Engine (ISE), including a severe zero-day flaw identified as CVE-2026-76460. This authentication bypass vulnerability affects an API in ISE, which is a key component of Cisco's network access control and zero-trust solutions. The vulnerability arises from insufficient authentication controls on an ISE API endpoint, allowing attackers to potentially gain unauthorized access by sending crafted requests.
The flaw was revealed and patched earlier this week, with the Cybersecurity and Infrastructure Security Agency (CISA) quickly adding it to its Known Exploited Vulnerabilities catalog. Cisco also addressed other related vulnerabilities in ISE and the ISE Passive Identity Connector that share similar authentication issues.
The exploitation of CVE-2026-76460 is particularly concerning because it allows attackers to achieve root privileges and execute commands on affected systems without needing user interaction. Furthermore, since ISE is used by other Cisco APIs for managing authentication and access, compromising ISE can have wide-reaching implications, potentially leading to unauthorized network access and further breaches.
Cisco advises users to apply the latest patches for ISE versions 3.1 through 3.5. The company has suggested using infrastructure access control lists as a temporary mitigation measure, though it stresses that these are not permanent solutions. Cisco also recommends monitoring network and firewall logs for unusual activity to detect any signs of exploitation.
This incident highlights the ongoing challenges of securing API endpoints across the industry. Experts, including Johannes Ullrich from the SANS Internet Storm Center, note that missing authentication for API endpoints is a widespread issue, exacerbated as APIs become more exposed in modern web applications.

