ZeroHour
CSO Onlinepublished ()ingested 2· 2 reads

Cisco patches max-severity ISE flaw, the second critical zero-day this week

criticalExploit / PoC exploited in the wildimportance 92CVE-2026-76460CVE-2026-20079CVE-2026-20131
AI summary · glm-5.3-flash

Cisco emergency-patched actively exploited CVE-2026-76460 (CVSS 10.0), an unauthenticated API flaw granting root on ISE appliances; CISA added it to KEV.

Cisco patched CVE-2026-76460, a CVSS 10.0 authentication bypass in a Cisco Identity Services Engine management API that lets unauthenticated attackers gain root privileges. It affects ISE and ISE-PIC in all configurations and is fixed in 3.1 Patch 12 through 3.5 Patch 4. CISA added the flaw to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation. A broader review fixed 21 critical ISE flaws plus high- and medium-severity issues, following earlier exploited firewall flaws CVE-2026-20079 and CVE-2026-20131.

  • Unauthenticated crafted API requests bypass the web management interface and yield root access.
  • CISA added CVE-2026-76460 to the KEV catalog, confirming in-the-wild exploitation.
  • Comprehensive ISE review fixed 21 critical flaws, three high, and 18 medium severity issues.
  • Cisco advises iACLs, log review for suspicious usernames, and re-imaging suspected nodes.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20131
Unauthenticated Java Deserialization RCE in Cisco FMC and SCC

CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization.

10.033% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC) Software version ranges not yet published in available data
  • Cisco Security Cloud Control (SCC) Firewall Management version ranges not yet published in available data
largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed
CVE-2026-76460
Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC

Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.

Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface.

10.0 KEV PoC
  • Cisco Identity Services Engine (ISE)
  • Cisco ISE Passive Identity Connector (ISE-PIC)
large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces
Full article440 words · extracted from csoonline.com · click to collapse

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway appliance.

The Cisco ISE flaw, tracked as CVE-2026-76460, has the maximum severity score of 10.0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device. The vulnerability is in an API endpoint used for management and can be exploited by sending crafted requests that bypass the normal web-based management interface completely.

The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, depending on which major software release is being used.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, indicating that exploitation in the wild has been confirmed.

Mitigation

Users of Cisco ISE and ISE-PIC are advised to check the access.log on their devices and search for suspicious usernames, which could be an indicator of successful compromise. However, because attackers gain root access through this vulnerability, they could delete the logs to hide their tracks, in which case network and firewall logs upstream of the devices should also be checked for suspicious activity such as file uploads and downloads initiated from the devices with unauthorized IP addresses.

“If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed,” the company said.

Cisco also advises administrators use infrastructure access control lists (iACLs) to limit who can send management and control traffic to the affected devices.

More critical flaws patched in Cisco ISE

This is not the only vulnerability fixed in Cisco ISE this week. The company did a comprehensive review of the Cisco ISE and ISE-PIC platforms, uncovering and fixing a total of 21 critical vulnerabilities, including remote code execution ones and other API flaws that fall in the same class as CVE-2026-76460. The releases also address three high-severity flaws and 18 medium-severity ones.

Separately the company also patched critical- and medium-severity flaws in Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software. Older vulnerabilities in these products have been exploited by different threat actors this year, particularly CVE-2026-20079 and CVE-2026-20131 affecting the FMC software that were originally patched in March.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4223535/cisco-patches-max-severity-ise-flaw-the-second-critical-zero-day-this-week.html