Skip to content
TrustList
News

Cisco ISE flaw CVE-2026-76460 is being exploited, scores 10 and has no workaround

Editorial

By TrustList Editorial

Cisco said on 16 September that CVE-2026-76460, an unauthenticated API bypass giving root on ISE and ISE-PIC, is being exploited and has no workaround; patches are out. CISA listed it the same day with a 19 September deadline.

About Cisco ISE flaw CVE-2026-76460 is being exploited, scores 10 and has no workaround

Cisco ISE flaw CVE-2026-76460 is being exploited, scores 10 and has no workaround

22 September 2026 — Cisco published a security advisory on 16 September 2026 for CVE-2026-76460, an authentication bypass in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Cisco gives it a CVSS base score of 10.0, the maximum, says there are no workarounds, and says its product security team is aware of active exploitation. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalogue the same day.

The details

According to Cisco, the flaw comes from insufficient authentication control on an API endpoint. An unauthenticated attacker who can reach the device could send crafted requests, bypass the web-based management interface and run commands as root. It affects ISE and ISE-PIC whatever their configuration. Cisco says the flaw was found while resolving a Technical Assistance Center support case.

First fixed releases, for both ISE and ISE-PIC:

  • 3.1 Patch 12
  • 3.2 Patch 11
  • 3.3 Patch 12
  • 3.4 Patch 7
  • 3.5 Patch 4

Release 3.0 has reached End of Software Maintenance, and Cisco advises moving to a supported release that includes the fix. There is no workaround, but Cisco says infrastructure access control lists that allow only the management and control traffic a device needs can reduce exposure.

Because a successful attacker has root access, Cisco warns that evidence of exploitation may be removed or hidden. It advises reviewing the access log for suspicious usernames, on every node in a distributed deployment, and, if compromise is suspected, re-imaging the affected nodes and restoring from a configuration backup.

CISA's catalogue entry sets a due date of 19 September 2026 for US federal civilian agencies, marks the flaw for forensic triage and lists ransomware use as unknown. The Register reported on 17 September that Cisco has not said who is exploiting the flaw, for how long, or what attackers did afterwards.

Why it matters

ISE decides which users and devices may join a corporate network. An attacker with root on an ISE node sits inside that access control system, which is why Cisco and CISA are treating this as urgent.

What to do

  • Identify every ISE and ISE-PIC node, including any run by a managed service provider, and record its release and patch level.
  • Apply the first fixed patch for your release line now. If you are on 3.0 or earlier, plan an urgent migration.
  • Until patched, restrict access to the management interface and APIs with access control lists.
  • Review the access logs on every node for suspicious usernames, as Cisco describes.
  • If you find signs of compromise, re-image and restore as Cisco advises, and consider rotating credentials the system holds, such as administrator accounts and directory connections.
  • Ask your managed service provider for written confirmation of when each node was patched.

What the advisory leaves out

Cisco has not said how many customers have been attacked or when exploitation began. CISA's due date applies to US federal agencies, but it is a useful benchmark for everyone else.

Sources