
Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack
Cisco has released a fix for a maximum-severity flaw in its Identity Services Engine (ISE) platform after confirming the bug was already being exploited by attackers. The vulnerability, tracked as CVE-2026-76460, carries a perfect CVSS score of 10.0 and was patched by Cisco on September 16, 2026.
The flaw sits in an API within Cisco Identity Services Engine and stems from inadequate authentication checks on an API endpoint. Because of this weakness, an unauthenticated attacker could send a specially crafted request to that endpoint and slip past ISE's web-based management interface entirely, gaining unauthorized access to the device without needing valid credentials.
CISA Adds CVE-2026...