CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)
CISA added actively exploited Cisco ISE authentication bypass CVE-2026-76460 to its KEV catalog, urging patches by September 19, 2026.
Cisco patched CVE-2026-76460, a critical authentication bypass in Cisco Identity Services Engine and ISE Passive Identity Connector caused by insufficient authentication controls on an API endpoint. An unauthenticated remote attacker can send a crafted request to bypass the web-based management interface and gain unauthorized access. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and set a September 19, 2026 remediation deadline. Fixed releases span ISE 3.1 Patch 12 through 3.5 Patch 4; release 3.0 is end-of-maintenance and requires an upgrade.
- Flaw stems from insufficient authentication controls on an API endpoint, allowing unauthenticated management interface access.
- Affects Cisco ISE and ISE-PIC regardless of configuration; fixed in patches for releases 3.1 through 3.5.
- CISA set a September 19, 2026 remediation deadline; ISE 3.0 requires upgrade to a supported release.
- Defenders can check ise-kong/access.log for suspicious usernames; Qualys QID 317886 detects vulnerable assets.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces |
Full article367 words · extracted from threatprotect.qualys.com · click to collapse
Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to bypass authentication. Cisco mentioned in their advisory that they are aware of active exploitation of this vulnerability.
CISA acknowledged the active exploitation of the vulnerability by adding to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch it before September 19, 2026.
Cisco Identity Services Engine (ISE) is a network security system that helps ensure that only trusted users and devices can access network resources. ISE is a standard policy engine that enables endpoint access control and network device administration.
Vulnerability Details
This vulnerability stems from insufficient authentication controls on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. Upon successful exploitation, an attacker could gain unauthorized access to the affected device by bypassing the web-based management interface.
Indicators of Compromise
To confirm any attempts to exploit this vulnerability, users can review the access.log and look for suspicious usernames. If the device is part of a distributed deployment, review the logs of each node. The following is a non-exhaustive example of how a suspicious username could be detected in the logs:
admin#show logging application ise-kong/access.log | include dummyuser
To view additional access.log files, collect a support bundle with include debug logs selected, use shared key encryption, and then decrypt and find the access logs at ./ise/logs/apigateway/access.log..gz.
Affected and Patched Versions
The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
| Cisco ISE or ISE-PIC Release | First Fixed Release |
|---|---|
| 3.1 | 3.1 Patch 12 |
| 3.2 | 3.2 Patch 11 |
| 3.3 | 3.3 Patch 12 |
| 3.4 | 3.4 Patch 7 |
| 3.5 | 3.5 Patch 4 |
Note: Cisco ISE Software Release 3.0 has reached End of Software Maintenance. Users must upgrade to migrate to a supported release that includes the fix for this vulnerability.
For more information, please refer to Cisco Security Advisory (cisco-sa-ISE-ABP-VNSW7Tn5).
Qualys Detection
Qualys customers can scan their devices with QID 317886 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
Text extracted automatically; images, tables and formatting may be missing. Original: https://threatprotect.qualys.com/2026/09/17/cisa-warns-of-cisco-identity-services-engine-authentication-bypass-vulnerability-cve-2026-76460/