Cisco Warns of Active Exploitation of Critical ISE Flaw
Cisco warns that CVE-2026-76460 (CVSS 10.0) in Identity Services Engine is actively exploited, enabling unauthenticated root access; CISA added it to KEV.
Cisco disclosed CVE-2026-76460, a CVSS 10.0 flaw caused by insufficient control of an API endpoint in Cisco ISE and ISE-PIC, allowing crafted requests to bypass the web-based management interface and potentially obtain root command execution. Active exploitation is confirmed; patches are available and no workarounds exist, though infrastructure access control lists can restrict management traffic as an interim measure. CISA added the flaw to its Known Exploited Vulnerabilities catalog, requiring FCEB agencies to prioritize patching. Cisco urges checking access.log on every node, reimaging suspected compromised nodes, and reviewing external firewall logs for unexpected uploads.
- Actively exploited maximum-severity flaw in Cisco ISE and ISE-PIC
- Affects all device configurations; no workarounds, only iACL mitigation
- CISA KEV listing obligates federal civilian agencies to patch promptly
- Root-level access lets attackers erase forensic evidence on nodes
- Cisco advises reimaging and restoring from known-good backups if compromised
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces |
Full article423 words · extracted from infosecurity-magazine.com · click to collapse
Cisco has warned customers of the active exploitation of a maximum severity flaw affecting its Cisco Identity Services Engine (ISE) product.
The flaw, CVE-2026-76460, is due to insufficient control on an API endpoint. It has a maximum CVSS rating of 10.0.
“An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface,” Cisco wrote in its update dated September 16.
The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
The tech giant has released software updates to address the flaw and urged customers to upgrade to prevent exploitation.
There are no workarounds that address the vulnerability. However, customers can use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device to prevent remote exploitation prior to applying the software update.
Following Cisco’s public disclosure, the US Cybersecurity and Infrastructure Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog. This requires Federal Civilian Executive Branch (FCEB) agencies to prioritize applying a patch for the vulnerability.
Cisco ISE is a centralized security policy management platform that controls network access across wired, wireless and VPN connections.
Cisco Customers Told to Check for Signs of Exploitation
Cisco also recommended that ISE customers look for indicators of attempted exploitation of the vulnerability.
Security teams should review the access.log and look for suspicious usernames, with Cisco providing an example of how this may look.
“The presence of any entry in the output may indicate malicious activity. This should be done on every node in the deployment. If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed,” Cisco said.
The firm also warned that successful exploitation could result in attackers obtaining command execution with root privilege – a level of access that could allow them to remove or hide evidence of exploitation and indicators of compromise.
Therefore, Cisco strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity. This includes unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.
The Cisco update is part of a group of advisories issued by the company, which highlights a range of other vulnerabilities of varying degrees of severity and their available fixes.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/