ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 9 sources: “Cisco Emergency-Patches Actively Exploited CVSS 10.0 Zero-Day CVE-2026-76460 in Identity Services Engine; CISA Adds to KEV” — merged summary and timeline →

Cisco security advisory (AV26-932)

highAdvisory exploited in the wildimportance 72CVE-2026-76460
AI summary · glm-5.3-flash

Cisco September 2026 updates fix flaws in ASA, FTD, FMC, ISE, and Nexus Dashboard; CISA added actively exploited CVE-2026-76460 to KEV.

Cisco's September 2026 hardening releases address vulnerabilities across Secure Firewall Threat Defense and Management Center, ASA, Identity Services Engine, ISE-PIC, and Nexus Dashboard, with fixes in branches such as FTD/FMC 7.0.10-10.1.0, ASA 9.16.4.103-9.24.1.26, and ISE 3.1 Patch 12-3.5 Patch 4. CISA added CVE-2026-76460, a Cisco Identity Services Engine authentication bypass, to its Known Exploited Vulnerabilities catalog on September 16, 2026. The Canadian Centre for Cyber Security urges users and administrators to review the advisories and apply the updates.

  • CISA added CVE-2026-76460 (ISE authentication bypass) to KEV on September 16, 2026
  • Affected products include Cisco FTD, FMC, ASA, ISE, ISE-PIC, and Nexus Dashboard
  • Canadian Cyber Centre urges administrators to apply updated releases

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76460
Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC

Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.

Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface.

10.0 KEV PoC
  • Cisco Identity Services Engine (ISE)
  • Cisco ISE Passive Identity Connector (ISE-PIC)
large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces
Full article209 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-932
Date: September 17, 2026

As of September 16, 2026, Cisco is affected by vulnerabilities in the following products:

  • Cisco Secure Firewall Threat Defense (FTD) Software
    • Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0
  • Cisco Secure Firewall Management Center (FMC) Software
    • Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0
  • Cisco Identity Services Engine (ISE) Software
    • Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4
  • Cisco ISE Passive Identity Connector (ISE-PIC) Software
    • Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4
  • Cisco Nexus Dashboard
    • Prior to 4.3.1.175
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
    • Prior to 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47 and 9.24.1.26

On September 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-932