CVE-2026-76460 lets an unauthenticated attacker bypass Cisco Identity Services Engine's management interface through an API endpoint and run commands as root. Cisco confirmed active exploitation; CISA gave federal agencies until September 19.