Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-76423: The Cisco ISE REST API Flaw That Hands Out Admin Without a Password

CVE-2026-76423: The Cisco ISE REST API Flaw That Hands Out Admin Without a Password Vulnerability overview Cisco published a set of security advisories on 16 September 2026 covering its Identity Services Engine (ISE) product line. The most severe item is CVE-2026-76423, an authentication bypass in the ISE REST API that carries a CVSS v3 base score of 10.0. Cisco's advisory states the root cause…

On 16 September 2026, Cisco issued a set of security advisories covering its Identity Services Engine (ISE) product line, including a severe authentication bypass vulnerability in the ISE REST API. This vulnerability, CVE-2026-76423, has a CVSS v3 base score of 10.0, making it highly critical. The root cause is insufficient authorization checks on the REST API web service, allowing an unauthenticated, remote attacker to gain administrative access to the appliance.

This flaw is not isolated, as it was shipped alongside other related issues, such as CVE-2026-20130 (hardening-release improper neutralization), CVE-2026-20307 (insecure deserialization leading to remote code execution), CVE-2026-20305 (command injection in diagnostic tooling), and CVE-2026-20284 (SQL injection in the SXP REST API), all with a CVSS v3 base score of 10.0 or higher.

Cisco has stated it is not aware of malicious exploitation of these specific CVEs at the time of disclosure. The vulnerability affects Cisco Identity Services Engine and Cisco ISE Passive Identity Connector software versions 3.1 to 3.5. An attacker only needs IP-level access to the ISE REST API, which is typically on a management network rather than the public internet.

Once network reachability to the API is established, no authentication or user interaction is required. Compromising ISE can lead to significant impacts, such as reading and altering identity data, changing authorization policies, modifying network device integrations, and using the appliance as a pivot point into the corporate network.

Cisco has released fixed builds for the affected versions, and organizations running older releases should migrate to a supported branch as part of the remediation process.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

The Machine That finally Wake Up

The screen stayed black. I had rebooted the laptop without really thinking about it. Just a normal restart. I was expecting the usual logo, a few seconds of waiting, then the desktop. Nothing happened. No logo. No error. No helpful message. Just a black screen. That was the point where I stopped treating it like a minor problem.

  • Laptop screen remained black despite routine reboot.
  • Filesystem corruption caused by shared partition issues.
  • JAZZ AI system successfully booted on non-prepared laptop.

More from Friday 18 September →