CVE Research
sekurity-team
InSEKurity of the Week (CW38/2026): Cisco ISE Authentication Bypass via Privileged API (CVE-2026-76460)
One crafted request to an unauthenticated API endpoint hands an attacker the box that decides who is allowed on your network -- and then root on it. CVSS 10.0, exploited as a zero-day, in CISA KEV on September 16 with a three-day federal deadline, and no workaround that does not involve an ACL.
Exploit
01
