Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Cisco urgently patched actively exploited zero-day CVE-2026-76460 (CVSS 10.0), an ISE authentication bypass enabling root command execution; CISA added it to KEV.
Cisco released emergency patches for CVE-2026-76460 (CVSS 10.0), a zero-day authentication bypass in an API endpoint of Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), and confirmed active exploitation in the wild. Successful exploitation lets attackers bypass the web-based management interface and execute commands with root privileges, allowing them to hide or delete indicators of compromise. Fixed releases are ISE/ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, and 3.1 Patch 12; no workarounds exist beyond restricting traffic with infrastructure ACLs. CISA added the flaw to its Known Exploited Vulnerabilities catalog, giving US federal agencies three days to patch under BOD 26-04.
- CVE-2026-76460 affects ISE and ISE-PIC regardless of device configuration; exploitation grants root-level command execution.
- Cisco PSIRT confirms active exploitation but has not attributed the attacks to any threat actor.
- Defenders should review access.log for suspicious usernames on every node in distributed deployments.
- Compromised nodes should be re-imaged and restored from configuration backups.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces |
Full article391 words · extracted from securityweek.com · click to collapse
Cisco on Wednesday released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) that has been exploited in the wild as a zero-day.
Tracked as CVE-2026-76460 (CVSS score of 10/10), the security defect impacts an API endpoint of the appliance, which does not apply sufficient authentication controls.
This allows an attacker to send crafted requests to the API and bypass the web-based management interface to gain access to the affected device.
Both Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected, regardless of device configuration. While no workarounds exist, using infrastructure access control lists (iACLs) to restrict traffic to the affected device prevents remote exploitation.
To resolve the bug, customers should upgrade to ISE or ISE-PIC versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12.
“The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company notes in its advisory.
Advertisement. Scroll to continue reading.
Cisco has not shared any information on who is behind the attacks. Cybercriminals and state-sponsored threat actors regularly target vulnerabilities in the company’s products.
To hunt for potential compromises, organizations should review ‘access.log’ for suspicious usernames. For distributed deployments, the logs for each node should be checked.
“The presence of any entry in the output may indicate malicious activity. This should be done on every node in the deployment. If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed,” the company says.
Additionally, Cisco warns that successful exploitation of CVE-2026-76460 can enable attackers to execute commands with root privileges, which would allow them to hide or delete indicators of compromise (IoCs).
Cross-checking network logs and firewall logs outside of the impacted device should help administrators discover potential compromises, including unexpected uploads/downloads.
On Wednesday, the US cybersecurity agency CISA added the zero-day to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04 requirements.
Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Related: Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Related: Chrome, Firefox Updates Patch 115 Vulnerabilities
Related: Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/