Threat Advisory

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected (CVE-2026-76423)

CRITICAL CVSS 10 September 16, 2026

What happened

A critical vulnerability has been identified in the REST API of Cisco ISE and Cisco ISE-PIC, potentially allowing unauthenticated, remote attackers to gain administrative access to affected devices. This flaw stems from insufficient authorization checks in the exposed REST API web service, enabling exploitation through crafted HTTP requests sent directly to the exposed API port. Successful exploitation could result in attackers reading and modifying configuration and identity data with administrative privileges, leading to a high impact on affected systems. The vulnerability was reported by the NVD and is designated CVE-2026-76423, with a CVSS score of 10.0, indicating maximum severity. Exploitation conditions include remote network access to the exposed service, with no prior access or user interaction required from the attacker. The flaw is associated with CWE-290, reflecting inadequate access controls in authentication mechanisms.

Who is affected

Organisations running Cisco ISE or Cisco ISE-PIC are potentially affected by this vulnerability. Affected deployments are those where the REST API web service is exposed over the network without sufficient access controls, and where attackers can send crafted HTTP requests directly to the affected port. The vulnerability’s exploitation does not require prior access or user interaction, which could facilitate widespread and automated attack attempts on vulnerable systems. As the precise versions impacted have not been specified, all affected deployments are advised to assess their exposed services and implementation configurations.

Recommended actions

  1. Implement network segmentation and access controls to restrict access to the REST API port, ensuring only trusted systems can communicate with it.
  2. Monitor network traffic for unusual or suspicious activity directed at the exposed REST API service.
  3. Review and update configurations to limit exposure of the REST API service where possible.
  4. Apply vendor security updates or patches promptly when they become available, and confirm the security posture of affected systems.
  5. Maintain an effective inventory of affected devices and regularly review network security practices to minimise attack surfaces.

Indicators of compromise

None provided at this time.

Affected

Vendors: Cisco

Products: Cisco ISE, Cisco ISE-PIC

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severitycritical
CVSS10
CVECVE-2026-76423
PublishedSeptember 16, 2026
VendorCisco
ProductsCisco ISE, Cisco ISE-PIC

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent