CVE-2026-76423: The Cisco ISE REST API Flaw That Hands Out Admin Without a Password Vulnerability overview Cisco published a set of security advisories on 16 September 2026 covering its Identity Services Engine (ISE) product line. The most severe item is CVE-2026-76423, an authentication bypass in the ISE REST API that carries a CVSS v3 base score of 10.0. Cisco's advisory states the root cause plainly: the REST API web service was exposed with insufficient authorization checks....