OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-76423

CRITICAL · CVSS 10 EPSS 0.58% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability in the REST API of Cisco Identity Services Engine (ISE) and Cisco ISE-PIC allows unauthenticated remote attackers to gain administrative access by exploiting insufficient authorization checks. This could enable attackers to read and modify sensitive configuration and identity data. Organizations using affected Cisco products should prioritize immediate remediation to mitigate the risk of unauthorized access and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76423
Severity
CRITICAL
CVSS
10
EPSS
0.58%
Cisco

Original NVD Description

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exploit could allow the attacker to read and modify ISE configuration and identity data with administrative privileges.