Cisco warns of max severity ISE zero-day exploited in attacks
Cisco patched CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine actively exploited in attacks; CISA added it to KEV with a three-day federal deadline.
CVE-2026-76460 is a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE-PIC, exploitable regardless of configuration, allowing attackers to access the web-based management interface. Cisco PSIRT confirmed active exploitation; no workarounds exist, and fixed releases are available for ISE 3.1 through 3.5, with re-imaging of suspect nodes recommended. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco also patched CVE-2026-76423 and five other critical ISE flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20284) that are not yet flagged as exploited.
- CVE-2026-76460 is an unauthenticated API authentication bypass in Cisco ISE and ISE-PIC, exploitable regardless of configuration
- Cisco PSIRT confirmed active exploitation; no workarounds exist, only fixed releases for ISE 3.1-3.5
- CISA added the flaw to the KEV Catalog and gave federal agencies three days to patch
- Cisco advises re-imaging suspect nodes, checking access.log for suspicious usernames, and reviewing firewall logs
- Cisco also patched CVE-2026-76423 and five other critical ISE flaws, none yet flagged as exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20337 | Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known. Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline. | 10.0 | 68% | KEV |
| moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts) | |
| CVE-2026-20176 +1 in the same advisory: …20211 | Authenticated Command Injection in Cisco Identity Services Engine (ISE) Cisco ISE contains a command injection flaw (CWE-77) caused by insufficient validation of user-supplied input. An authenticated, remote attacker who already holds valid high-privileged administrative credentials can send a crafted HTTP request to an affected device to run arbitrary commands on the underlying operating system, gaining system-level access and then elevating to root. In single-node deployments, successful exploitation can render the ISE node unavailable, causing a denial of service in which endpoints that have not yet authenticated cannot access the network until the node is restored. All Cisco ISE deployments are potentially affected, though exploitation requires stolen or compromised administrator credentials rather than anonymous access. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so exploitation has not been confirmed. Do: Upgrade to the fixed release specified in Cisco's PSIRT advisory for CVE-2026-20176 (not listed in this data). Until patched, restrict access to the ISE administration interface to trusted management networks, audit high-privileged admin accounts for compromise (since valid admin credentials are required), and monitor for unexpected root-level or shell activity on ISE appliances. Operators of single-node deployments should prepare failover/restore plans, as exploitation would block new endpoint network authentication until the node is recovered. | 9.1 | — |
| largelikely tens of thousands of enterprise ISE deployments/nodes worldwide (estimated) | ||
| CVE-2026-20284 | Authenticated SQL Injection in Cisco ISE SXP REST API Cisco ISE (Identity Services Engine) contains a SQL injection flaw (CWE-943) in its SXP REST API, caused by insufficient validation of user-supplied input in REST API calls. To trigger it, an attacker must send crafted input to the affected device while holding valid administrative credentials, with the SXP service enabled and at least one SXP connection configured. A successful exploit could let the attacker read or modify data in the underlying ISE database, and in single-node deployments could crash the node, denying network access to endpoints that have not yet authenticated. Any organization running Cisco ISE with SXP/TrustSec in this configuration is affected, though the admin-credential requirement makes insider or compromised-credential scenarios the primary risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not in CISA's KEV catalog. Do: Upgrade ISE nodes to the fixed release identified in Cisco's security advisory (not specified in the source data). As interim mitigation, restrict access to the ISE admin/REST API to trusted management networks, disable the SXP service on nodes that do not use it, and audit admin accounts for credential compromise. Monitor Cisco PSIRT for updated fixed-version guidance. | 9.1 | — |
| large≈10,000–100,000 ISE nodes worldwide (subset of tens of thousands of enterprise ISE deployments that have SXP enabled) | ||
| CVE-2026-20307 | Authenticated Java Deserialization RCE in Cisco ISE Web Management Interface Cisco Identity Services Engine (ISE) contains an insecure deserialization flaw (CWE-502) in its web-based management interface, caused by unsafe handling of a user-supplied Java byte stream. An attacker who already holds at least low-privileged administrative credentials can send a crafted serialized Java object to the management interface to trigger the flaw. Successful exploitation yields arbitrary code execution on the underlying operating system and privilege escalation to root; in single-node deployments it can also render the ISE node unavailable, blocking network access for endpoints that have not yet authenticated. All Cisco ISE deployments whose management interface is reachable by an attacker with administrative credentials are affected, though specific version ranges were not provided in the source data. As of now the flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known. Do: Upgrade affected ISE nodes to the fixed release identified in Cisco's advisory. Until patched, restrict access to the ISE web management interface to trusted administrative networks and audit which accounts hold low-privileged administrative credentials. Operators of single-node deployments should prioritize patching since exploitation would cause a full denial of network access for unauthenticated endpoints. | 9.9 | — |
| large≈10,000-100,000 enterprise ISE deployments worldwide, with only a subset exposing the management interface beyond trusted admin networks | ||
| CVE-2026-76423 | Unauthenticated Administrative Access via REST API Flaw in Cisco ISE and ISE-PIC Cisco ISE and Cisco ISE-PIC contain an authentication bypass (CWE-290) in their REST API web service, which is exposed with insufficient authorization checks. An unauthenticated, remote attacker can exploit it by sending a crafted HTTP request to the exposed REST API port, requiring no credentials or user interaction. A successful exploit grants administrative privileges over the device, letting the attacker read and modify ISE configuration and identity data. Any organization running an affected Cisco ISE or ISE-PIC deployment is affected, with risk highest where the REST API port is reachable from untrusted networks. No public proof-of-concept or in-the-wild exploitation is currently known, and the flaw is not yet listed in CISA's KEV catalog. Do: Upgrade ISE and ISE-PIC to the fixed releases identified in the Cisco PSIRT advisory for CVE-2026-76423. As an interim mitigation, restrict network access to the ISE REST API port to trusted management networks and disable the REST API service where it is not required. Review ISE logs for unauthenticated or anomalous administrative API requests, and treat configuration and identity data on exposed deployments as potentially compromised. | 10.0 | — |
| largeTens of thousands of enterprise/government deployments likely affected; directly internet-exposed REST API instances estimated in the low thousands | ||
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces |
Full article488 words · extracted from bleepingcomputer.com · click to collapse

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.
Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models.
The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.
"This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint," the company explained. "A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."
Cisco also warned customers on Wednesday to secure their systems since its Product Security Incident Response Team (PSIRT) flagged CVE-2026-76460 as actively exploited.
"The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
Because no workarounds exist, applying the security updates is the only recommended course of action to protect networks from ongoing attacks.
| Cisco ISE or ISE-PIC Release | First Fixed Release |
|---|---|
| 3.1 | 3.1 Patch 12 |
| 3.2 | 3.2 Patch 11 |
| 3.3 | 3.3 Patch 12 |
| 3.4 | 3.4 Patch 7 |
| 3.5 | 3.5 Patch 4 |
Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and "strongly" recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.
Admins should also cross-check firewall and network logs for signs of suspicious activity (including downloads and uploads from and to external or malicious IP addresses) because attackers may remove evidence of exploitation after obtaining command execution with root privileges.
Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and five other critical security issues (tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.
The Cybersecurity and Infrastructure Security Agency (CISA) also ordered federal agencies to patch their systems against CVE-2026-76460 within three days after adding it to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday.
In July 2025, threat actors exploited another Cisco ISE zero-day (CVE-2025-20337) with a maximum severity score in remote code execution attacks to deploy a custom "IdentityAuditAction" web shell disguised as a legitimate ISE component.
Over the last five years, CISA tagged 99 security flaws in Cisco products as actively exploited in attacks, including seven abused in ransomware attacks.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/