By Heath Callahan
Publication Date: 2026-09-16 17:58:00
Analysis
Nine CVEs in one identity platform — including two unauthenticated CVSS 10.0 bypasses under active exploitation — confirm that the infrastructure validating who gets on the network has become the primary attack surface.
Cisco disclosed nine vulnerabilities in its Identity Services Engine (ISE) on September 16, 2026, including multiple critical-severity flaws currently under active exploitation. The Cisco PSIRT advisory confirms that CVE-2026-76460, an unauthenticated REST API authentication bypass, carries a CVSS score of 10.0 and is being leveraged by attackers in the wild.
The discovery of CVE-2026-76460 occurred during the resolution of a Cisco Technical Assistance Center (TAC) support case. This detail confirms that at least one enterprise environment was already compromised before the vulnerability was identified and reported. The flaw allows unauthenticated attackers to bypass authentication mechanisms entirely, granting them unauthorized access to the…

