Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423
On September 16, 2026, CVE-2026-76423 was disclosed in Cisco Identity Services Engine: an unauthenticated attacker gains administrative access via REST API. Four other critical vulnerabilities were patched in the same cycle, including RCE and SQL injection. Fixes were released in patches 3.1–3.5.
- CVE-2026-76423 is an authorization bypass in ISE REST API, CVSS 10.0
- Cycle also includes CVE-2026-20307 (RCE, 9.9) and CVE-2026-20305 (9.1)
- Fixed in patches 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4
- Cisco has not reported real-world exploitation of these vulnerabilities
Read next
Security