
Cisco ISE CVE-2026-76460 CVSS 10.0 Auth Bypass Under Active Exploitation
Cisco ISE authentication bypass CVE-2026-76460 is actively exploited while parallel trust failures appear in AI coding agents and browser malware. Evidence trails show recurring verification gaps in management interfaces across sectors. Operational impact centers on rapid exposure of federal and enterprise deployments.
The flaw allows unauthenticated remote attackers to reach the web management interface without credentials. Cisco telemetry and incident reports show exploitation attempts against production ISE deployments, many of which sit in federal and enterprise networks per public procurement records. No public IOCs have been released, leaving defenders reliant on the advisory alone.
The same week saw Plugin4Shell demonstrated against four AI coding agents where SHA-pinning failed to prevent malicious plugin checkout from a controlled repository. This mirrors the ISE case: both exploit assumptions about upstream verification rather than runtime enforcement. AIR Security and libheif patch timelines indicate supply-chain trust failures recur when marketplaces prioritize speed.
KREMLIN malware delivery via browser hijacks and the NightmareStresser domain seizures point to the same operational pattern—abuse of trusted endpoints that lack independent attestation. Official Cisco and DOJ statements focus on patching and takedowns, yet contract data shows continued procurement of the affected platforms without mandatory API hardening audits.
CISA is expected to add the CVE to the KEV catalog; organizations should inventory ISE API exposure and enforce out-of-band verification for AI agent plugins within 30 days.
CISA: CVE-2026-76460 added to Known Exploited Vulnerabilities list within 30 days
Sources (3)
- [1]Cisco Security Advisory(https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-202609-ise)
- [2]The Hacker News Weekly Recap(https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html)
- [3]AIR Security Plugin4Shell Disclosure(https://air.security/research/plugin4shell)