CVE-2026-76460: Cisco Identity Services Engine Maximum CVSS 10.0 Zero-Day RCE & Authentication Bypass Breakdown
Technical teardown of CVE-2026-76460 in Cisco ISE: maximum CVSS 10.0 zero-day authentication bypass, root execution, and urgent patch deployment.
A maximum-severity CVSS 10.0 unauthenticated remote code execution and authentication bypass zero-day in Cisco Identity Services Engine (CVE-2026-76460) has been actively targeted in the wild to compromise enterprise network access control (NAC) policies.
CVE-2026-76460 (CWE-287 / CWE-94: Improper Authentication & Remote Code Execution)
Severity: Critical / Maximum Severity (CVSS 10.0)
Status: 🚨 Active In-the-Wild Zero-Day Exploitation / Emergency Cisco Patch
Affected Systems: Cisco ISE versions 3.1, 3.2, 3.3, 3.4, and 3.5 prior to hotfixed releases
Zero-Day Attack Path in Network Access Control
The vulnerability exists in the internal policy service node communication API. An unauthenticated remote actor can forge internal cluster authorization tokens, bypassing administrative validation to execute arbitrary root commands on the Cisco ISE appliance and grant unrestricted network admission.