Cisco ISE flaw CVE-2026-76460 is being exploited, scores 10 and has no workaround
EditorialBy TrustList Editorial
Cisco said on 16 September that CVE-2026-76460, an unauthenticated API bypass giving root on ISE and ISE-PIC, is being exploited and has no workaround; patches are out. CISA listed it the same day with a 19 September deadline.
About Cisco ISE flaw CVE-2026-76460 is being exploited, scores 10 and has no workaround
Cisco ISE flaw CVE-2026-76460 is being exploited, scores 10 and has no workaround
22 September 2026 — Cisco published a security advisory on 16 September 2026 for CVE-2026-76460, an authentication bypass in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Cisco gives it a CVSS base score of 10.0, the maximum, says there are no workarounds, and says its product security team is aware of active exploitation. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalogue the same day.
The details
According to Cisco, the flaw comes from insufficient authentication control on an API endpoint. An unauthenticated attacker who can reach the device could send crafted requests, bypass the web-based management interface and run commands as root. It affects ISE and ISE-PIC whatever their configuration. Cisco says the flaw was found while resolving a Technical Assistance Center support case.
First fixed releases, for both ISE and ISE-PIC:
- 3.1 Patch 12
- 3.2 Patch 11
- 3.3 Patch 12
- 3.4 Patch 7
- 3.5 Patch 4
Release 3.0 has reached End of Software Maintenance, and Cisco advises moving to a supported release that includes the fix. There is no workaround, but Cisco says infrastructure access control lists that allow only the management and control traffic a device needs can reduce exposure.
Because a successful attacker has root access, Cisco warns that evidence of exploitation may be removed or hidden. It advises reviewing the access log for suspicious usernames, on every node in a distributed deployment, and, if compromise is suspected, re-imaging the affected nodes and restoring from a configuration backup.
CISA's catalogue entry sets a due date of 19 September 2026 for US federal civilian agencies, marks the flaw for forensic triage and lists ransomware use as unknown. The Register reported on 17 September that Cisco has not said who is exploiting the flaw, for how long, or what attackers did afterwards.
Why it matters
ISE decides which users and devices may join a corporate network. An attacker with root on an ISE node sits inside that access control system, which is why Cisco and CISA are treating this as urgent.
What to do
- Identify every ISE and ISE-PIC node, including any run by a managed service provider, and record its release and patch level.
- Apply the first fixed patch for your release line now. If you are on 3.0 or earlier, plan an urgent migration.
- Until patched, restrict access to the management interface and APIs with access control lists.
- Review the access logs on every node for suspicious usernames, as Cisco describes.
- If you find signs of compromise, re-image and restore as Cisco advises, and consider rotating credentials the system holds, such as administrator accounts and directory connections.
- Ask your managed service provider for written confirmation of when each node was patched.
What the advisory leaves out
Cisco has not said how many customers have been attacked or when exploitation began. CISA's due date applies to US federal agencies, but it is a useful benchmark for everyone else.
Sources
- Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5: Cisco Identity Services Engine Authentication Bypass Vulnerability (version 1.0) — 16 September 2026
- CISA: Known Exploited Vulnerabilities catalogue, JSON feed (catalogue version 2026.09.21; CVE-2026-76460 added 16 September 2026) — 21 September 2026
- The Register: Cisco drops another exploited zero-day, this time a perfect 10 — 17 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.