AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460
Canada's Cyber Centre alerts on three actively exploited Cisco ISE/ISE-PIC vulnerabilities enabling unauthenticated administrative access and data tampering.
Canada's Cyber Centre issued alert AL26-021 for three flaws in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC): CVE-2026-20192 (improper access control, CWE-284), CVE-2026-76423 (authentication bypass by spoofing, CWE-290), and CVE-2026-76460 (incorrect use of privileged APIs, CWE-648). Successful exploitation could let unauthenticated attackers bypass authentication, gain administrative access, and read or modify ISE configuration and identity data. Cisco confirmed active exploitation of CVE-2026-76460, which CISA added to its KEV catalog on September 16, 2026. Fixes ship in ISE 3.1–3.5 patches, and defenders are urged to prioritize that CVE, restrict management interfaces, and hunt for IoCs.
- Three flaws: improper access control (CVE-2026-20192), authentication bypass (CVE-2026-76423), privileged API misuse (CVE-2026-76460)
- Cisco confirmed active exploitation of CVE-2026-76460; CISA added it to KEV on September 16, 2026
- Exploitation can grant unauthenticated administrative access to read/modify ISE configuration and identity data
- Fixed releases available for ISE 3.1–3.5; reimage and restore from known-good backups if compromise suspected
- Defenders urged to restrict management interfaces via ACLs, segmentation, and trusted admin networks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20192 | Critical Improper Access Control Flaws in Cisco ISE and ISE-PIC CVE-2026-20192 tracks a set of improper access control vulnerabilities (CWE-284) in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), discovered by Cisco's own engineering teams during a comprehensive internal security review. The flaws are addressed through a software hardening release rather than an externally reported incident, and Cisco has not disclosed granular per-flaw mechanics in the available data. The CVSS 3.1 score of 10.0 (critical) indicates the issues are remotely exploitable over a network without privileges or user interaction, with high impact to confidentiality, integrity, and availability across security scopes, meaning an attacker could gain broad access or control within affected deployments. All organizations running Cisco ISE or ISE-PIC are potentially affected. There is currently no known exploitation, no public proof-of-concept, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Review Cisco's security advisory (from Cisco PSIRT) to identify which ISE and ISE-PIC releases are affected, and apply the software hardening release as soon as practical. Until patched, restrict access to ISE administration, pxGrid, and passive-identity interfaces to trusted management networks, and monitor Cisco's advisory for updates on exploitation status. | 10.0 | — |
| largetens of thousands of enterprise ISE/ISE-PIC deployments worldwide, with only a smaller subset exposing management interfaces to untrusted networks | ||
| CVE-2026-76423 | Unauthenticated Administrative Access via REST API Flaw in Cisco ISE and ISE-PIC Cisco ISE and Cisco ISE-PIC contain an authentication bypass (CWE-290) in their REST API web service, which is exposed with insufficient authorization checks. An unauthenticated, remote attacker can exploit it by sending a crafted HTTP request to the exposed REST API port, requiring no credentials or user interaction. A successful exploit grants administrative privileges over the device, letting the attacker read and modify ISE configuration and identity data. Any organization running an affected Cisco ISE or ISE-PIC deployment is affected, with risk highest where the REST API port is reachable from untrusted networks. No public proof-of-concept or in-the-wild exploitation is currently known, and the flaw is not yet listed in CISA's KEV catalog. Do: Upgrade ISE and ISE-PIC to the fixed releases identified in the Cisco PSIRT advisory for CVE-2026-76423. As an interim mitigation, restrict network access to the ISE REST API port to trusted management networks and disable the REST API service where it is not required. Review ISE logs for unauthenticated or anomalous administrative API requests, and treat configuration and identity data on exposed deployments as potentially compromised. | 10.0 | — |
| largeTens of thousands of enterprise/government deployments likely affected; directly internet-exposed REST API instances estimated in the low thousands | ||
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces |
Full article590 words · extracted from cyber.gc.ca · click to collapse
Number: AL26-021
Date: September 17, 2026
Audience
This Alert is intended for IT professionals and managers.
Purpose
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Details
The Canadian Centre for Cyber Security (Cyber Centre) is aware of multiple vulnerabilities impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC)Footnote 1.
Successful exploitation could allow unauthenticated attackers to bypass authentication controls, gain administrative access, access or modify sensitive data, and potentially compromise affected systems.
In response to the vendor advisory released on September 16, 2026, the Cyber Centre released AV26-932 on September 17, 2026Footnote 2.
Tracked as CVE-2026-20192Footnote 3, this vulnerability is an Improper Access Control vulnerability (CWE-284)Footnote 4 that may allow an unauthenticated attacker to bypass security controls, access sensitive information, modify system configurations, and impact system availability.
Tracked as CVE-2026-76423Footnote 5, this vulnerability is an Authentication Bypass by Spoofing vulnerability (CWE-290)Footnote 6 that may enable the attacker to read and modify ISE configuration and identity data with administrative privileges.
Tracked as CVE-2026-76460Footnote 7, this vulnerability is an Incorrect Use of Privileged APIs vulnerability (CWE-648)Footnote 8 that may allow an attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has confirmed active exploitation of this vulnerability.
On September 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026–76460 to their Known Exploited Vulnerabilities (KEV) DatabaseFootnote 9.
Suggested actions
The Cyber Centre strongly recommends that organizations running Cisco ISE and ISE-PIC upgrade to the vendor-supported fixed software versions identified below.
| Affected product | Affected releases | Fixed releases |
|---|---|---|
| Cisco Identity Services Engine (ISE) or ISE-PIC | releases prior to 3.0 | Migrate to a fixed release |
| Cisco Identity Services Engine (ISE) or ISE-PIC | release 3.1 | 3.1 Patch 12 |
| Cisco Identity Services Engine (ISE) or ISE-PIC | release 3.2 | 3.2 Patch 11 |
| Cisco Identity Services Engine (ISE) or ISE-PIC | release 3.3 | 3.3 Patch 12 |
| Cisco Identity Services Engine (ISE) or ISE-PIC | release 3.4 | 3.4 Patch 7 |
| Cisco Identity Services Engine (ISE) or ISE-PIC | release 3.5 | 3.5 Patch 4 |
The Cyber Centre also recommends organizations to:
- Apply vendor-provided security updates immediately. Cisco has released fixes for all three vulnerabilities.
- Prioritize remediation of CVE-2026-76460 due to confirmed in-the-wild exploitation.
- Review access logs for indicators of compromise (IoC), particularly suspicious usernames and unexpected API activity.
- Restrict access to management interfaces through access control lists (ACL), network segmentation, and trusted administration networks where feasible.
- If compromise is suspected, re-image affected nodes and restore from known-good backups, as attackers may obtain elevated privileges and remove evidence of exploitation.
- Monitor firewall, network, and authentication logs for anomalous activity associated with affected systems.
Note: Organizations operating Common CriteriaFootnote 10 evaluated configurations should review Cisco's advisory and apply the recommended updates in accordance with their change management and certification requirements.
In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security ActionsFootnote 11 with an emphasis on the following topics:
- Consolidating, monitoring, and defending Internet gateways
- Patch operating systems and applications
- Harden operating systems and applications
- Isolate web-facing applications
Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal, or email [email protected].
References
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460