Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks
Cisco confirms zero-day CVE-2026-76460 (CVSS 10.0) in ISE is under active exploitation, granting unauthenticated root command execution; patches released.
Cisco's PSIRT issued an urgent advisory for CVE-2026-76460, an authentication bypass via insufficient controls on an API endpoint in Cisco ISE and ISE-PIC, confirmed to be actively exploited with a CVSS score of 10.0. Exploitation can yield root-level command execution, enabling persistence, credential theft, and lateral movement from the network policy platform. Fixed releases are ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4; EOL version 3.0 requires migration, and iACLs offer only temporary mitigation. The flaw was discovered while resolving a TAC support case, and Cisco provides hunting guidance including access.log review and firewall log analysis.
- Unauthenticated remote attackers can bypass the ISE management interface
- Successful exploitation may grant root command execution and full node control
- Fixed releases span ISE 3.1 Patch 12 through 3.5 Patch 4
- ISE 3.0 is end of maintenance and must be migrated
- Flaw discovered internally during a TAC support case
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces |
Full article572 words · extracted from cybersecuritynews.com · click to collapse
Cisco has issued an urgent security advisory for a critical zero-day vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The flaw, tracked as CVE-2026-76460, is already being actively exploited, according to Cisco’s Product Security Incident Response Team.
The vulnerability carries a maximum CVSS score of 10.0. It could allow an unauthenticated remote attacker to bypass authentication on affected systems.
Cisco confirmed that no workaround is available, making immediate software updates the primary remediation step. The issue stems from insufficient authentication controls on an API endpoint in Cisco ISE.
An attacker can send a specially crafted request to the vulnerable endpoint and gain unauthorized access by bypassing the web-based management interface.
Cisco ISE is widely used by organizations to control network access, enforce security policies, authenticate users and devices, and provide visibility into connected assets.
Cisco ISE 0-Day Vulnerability Exploited
A successful compromise could therefore give attackers a high-value entry point into enterprise identity and network-management environments. Cisco warned that successful exploitation may allow threat actors to obtain command execution with root privileges.
Root-level access would provide full control over an affected ISE node, allowing attackers to alter configurations, deploy malicious tools, create persistence, steal credentials, or use the appliance as a staging point for lateral movement.
The vulnerability affects Cisco ISE and Cisco ISE-PIC regardless of device configuration. Cisco ISE Software Release 3.0 is also exposed, but it has reached the end of software maintenance. Organizations using version 3.0 should migrate to a supported release that includes the security fix.
Cisco released patches for supported versions of the platform. The fixed releases are ISE 3.1 Patch 12, ISE 3.2 Patch 11, ISE 3.3 Patch 12, ISE 3.4 Patch 7, and ISE 3.5 Patch 4.
Administrators should identify their deployed version and upgrade to the appropriate fixed release as soon as possible. For organizations unable to patch immediately, Cisco recommends using infrastructure access control lists, or iACLs, to limit management and control-plane traffic reaching vulnerable devices.
Only essential and trusted systems should be allowed to communicate with Cisco ISE management interfaces. However, Cisco stressed that this mitigation is only temporary and does not remove the underlying vulnerability.
Administrators should also investigate systems for signs of exploitation. Cisco advised reviewing the access.log file for suspicious usernames or unexpected API activity.
In distributed ISE environments, check every node because an attacker may target any accessible node. Cisco provided an example command for reviewing suspicious login-related events: show logging application ise-kong/access.log | include dummyuser.
Security teams should collect support bundles with debug logs enabled to access additional API gateway logs. Cisco noted that evidence on a compromised device may be incomplete because attackers with root-level access could remove or hide forensic artifacts.
Organizations should also examine firewall and network logs outside the affected appliance. Unexpected uploads from an ISE node to external IP addresses, suspicious downloads, and unexplained outbound connections may indicate compromise.
If malicious activity is identified or strongly suspected, Cisco recommends reimaging affected ISE nodes and restoring configurations from a known-good backup. The vendor discovered the vulnerability while resolving a Cisco Technical Assistance Center support case.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/cisco-warns-of-critical-ise-0-day-vulnerability-exploited/