Cisco patched CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine actively exploited in attacks; CISA added it to KEV with a three-day federal deadline.
CVE-2026-76460 is a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE-PIC, exploitable regardless of configuration, allowing attackers to access the web-based management interface. Cisco PSIRT confirmed active exploitation; no workarounds exist, and fixed releases are available for ISE 3.1 through 3.5, with re-imaging of suspect nodes recommended. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco also patched CVE-2026-76423 and five other critical ISE flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20284) that are not yet flagged as exploited.
Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC
CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.
Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC
Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.
· Cisco Identity Services Engine (ISE) · Cisco ISE Passive Identity Connector (ISE-PIC) KEV PoC large
Unauthenticated Administrative Access via REST API Flaw in Cisco ISE and ISE-PIC
Cisco ISE and Cisco ISE-PIC contain an authentication bypass (CWE-290) in their REST API web service, which is exposed with insufficient authorization checks. An unauthenticated, remote attacker can exploit it by sending a crafted HTTP request to the exposed REST API port, requiring no credentials or user interaction. A successful exploit grants administrative privileges over the device, letting the attacker read and modify ISE configuration and identity data. Any organization running an affected Cisco ISE or ISE-PIC deployment is affected, with risk highest where the REST API port is reachable from untrusted networks. No public proof-of-concept or in-the-wild exploitation is currently known, and the flaw is not yet listed in CISA's KEV catalog.
Authenticated Java Deserialization RCE in Cisco ISE Web Management Interface
Cisco Identity Services Engine (ISE) contains an insecure deserialization flaw (CWE-502) in its web-based management interface, caused by unsafe handling of a user-supplied Java byte stream. An attacker who already holds at least low-privileged administrative credentials can send a crafted serialized Java object to the management interface to trigger the flaw. Successful exploitation yields arbitrary code execution on the underlying operating system and privilege escalation to root; in single-node deployments it can also render the ISE node unavailable, blocking network access for endpoints that have not yet authenticated. All Cisco ISE deployments whose management interface is reachable by an attacker with administrative credentials are affected, though specific version ranges were not provided in the source data. As of now the flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known.
Authenticated Command Injection in Cisco Identity Services Engine (ISE)
Cisco ISE contains a command injection flaw (CWE-77) caused by insufficient validation of user-supplied input. An authenticated, remote attacker who already holds valid high-privileged administrative credentials can send a crafted HTTP request to an affected device to run arbitrary commands on the underlying operating system, gaining system-level access and then elevating to root. In single-node deployments, successful exploitation can render the ISE node unavailable, causing a denial of service in which endpoints that have not yet authenticated cannot access the network until the node is restored. All Cisco ISE deployments are potentially affected, though exploitation requires stolen or compromised administrator credentials rather than anonymous access. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so exploitation has not been confirmed.
Authenticated Java Deserialization RCE in Cisco Identity Services Engine (ISE)
CVE-2026-20211 is an insecure deserialization flaw (CWE-502) in Cisco Identity Services Engine that stems from the software deserializing untrusted Java objects. An authenticated, remote attacker who already holds valid high-privileged administrative credentials can send a crafted serialized Java object to an affected device, gaining user-level command execution on the underlying operating system and then escalating to root. A compromised node therefore exposes the full ISE appliance, and in single-node deployments exploitation can render the ISE node unavailable, blocking network access for endpoints that have not yet authenticated. All Cisco ISE deployments are potentially affected, though exploitation requires possession of top-tier admin credentials, which materially limits the attacker pool. As of this analysis there is no known public proof-of-concept and the flaw is not listed in CISA's KEV, so exploitation is not known to be occurring.
Authenticated SQL Injection in Cisco ISE SXP REST API
Cisco ISE (Identity Services Engine) contains a SQL injection flaw (CWE-943) in its SXP REST API, caused by insufficient validation of user-supplied input in REST API calls. To trigger it, an attacker must send crafted input to the affected device while holding valid administrative credentials, with the SXP service enabled and at least one SXP connection configured. A successful exploit could let the attacker read or modify data in the underlying ISE database, and in single-node deployments could crash the node, denying network access to endpoints that have not yet authenticated. Any organization running Cisco ISE with SXP/TrustSec in this configuration is affected, though the admin-credential requirement makes insider or compromised-credential scenarios the primary risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not in CISA's KEV catalog.
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.