Cisco Emergency-Patches Actively Exploited CVSS 10.0 Zero-Day CVE-2026-76460 in Identity Services Engine; CISA Adds to KEV
Cisco released emergency fixes (September 16, 2026) for CVE-2026-76460 (CVSS 10.0), an actively exploited unauthenticated authentication bypass in Cisco ISE and ISE-PIC API endpoints granting root command execution; no workarounds exist and CISA added it to…
Cisco's advisory cisco-sa-ISE-ABP-VNSW7Tn5 (September 16, 2026) describes CVE-2026-76460 (CVSS 10.0), insufficient authentication controls (CWE-648, Bug ID CSCww39530) on an API endpoint of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), affecting releases 3.0-3.5 regardless of device configuration. Cisco PSIRT confirmed active exploitation in the wild: a remote, unauthenticated attacker can send a crafted request to bypass the web-based management interface and execute commands with root privileges, enabling log deletion/tampering, persistence, credential theft, policy modification, and lateral movement. The flaw was discovered while resolving a TAC support case, and no threat actor has been attributed. Fixed releases are ISE/ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4; end-of-maintenance ISE 3.0 requires migration. No workarounds exist, though infrastructure ACLs (iACLs) restricting management traffic offer only temporary mitigation. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16, 2026, obligating US federal civilian agencies to patch promptly (SecurityWeek reports a three-day deadline under BOD 26-04). Cisco published IoCs and hunting guidance: check access.log for suspicious usernames on every node in distributed deployments, cross-check external firewall/network logs for unexpected uploads, and re-image suspected compromised nodes, restoring from known-good configuration backups. This is Cisco's second actively exploited zero-day in as many days, following CVE-2026-76461 (CVSS 9.8 per The Register) in Secure Email Gateway and Secure Email and Web Manager, disclosed days earlier (Help Net Security says two days). CyberScoop counts it as the third actively exploited ISE flaw since June 2025, after CVE-2025-20337 and CVE-2025-20281, and notes it is unrelated to CVE-2026-76461.
- CVE-2026-76460 scores CVSS 10.0; classified as CWE-648 (incorrect use of privileged APIs / insufficient authentication controls); Cisco Bug ID CSCww39530; advisory cisco-sa-ISE-ABP-VNSW7Tn5 published September 16, 2026.
- Affects Cisco ISE and ISE-PIC releases 3.0 through 3.5 regardless of device configuration.
- A remote, unauthenticated attacker can send a crafted request to an ISE API endpoint to bypass the web-based management interface and execute commands with root privileges.
- Root-level access enables log deletion/tampering, persistence, credential theft, policy modification, and lateral movement from the network policy platform.
- Cisco PSIRT confirmed active exploitation in the wild; the flaw was found during a TAC support case and no threat actor has been attributed.
- Fixed releases: ISE/ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4; ISE 3.0 is end-of-maintenance and requires migration.
- No workarounds exist; infrastructure ACLs restricting management traffic serve only as temporary mitigation.
- CISA added CVE-2026-76460 to the KEV catalog on September 16, 2026; SecurityWeek reports federal agencies have three days to patch under BOD 26-04, while Infosecurity Magazine notes FCEB agencies must prioritize patching.
Coverage timelineoldest first · each row is one article
- · 1d agoActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
SecurityWeek· 88
Cisco urgently patched actively exploited zero-day CVE-2026-76460 (CVSS 10.0), an ISE authentication bypass enabling root command execution; CISA added it to KEV.
- · 1d agoHackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Access
GBHackers· 78
Cisco patched CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE and ISE-PIC that can grant unauthenticated attackers root access.
- · 1d agoUnauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Help Net Security· 85
Cisco confirmed CVE-2026-76460, an actively exploited unauthenticated authentication bypass in Cisco ISE APIs, urging immediate patching with no workarounds available.
- · 1d agoCisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks
Cyber Security News· 86
Cisco confirms zero-day CVE-2026-76460 (CVSS 10.0) in ISE is under active exploitation, granting unauthenticated root command execution; patches released.
- · 1d agoCisco Warns of Active Exploitation of Critical ISE Flaw
Infosecurity Magazine· 90
Cisco warns that CVE-2026-76460 (CVSS 10.0) in Identity Services Engine is actively exploited, enabling unauthenticated root access; CISA added it to KEV.
- · 1d agoCisco drops another exploited zero-day, this time a perfect 10
The Register · Security· 90
Cisco's CVSS 10.0 CVE-2026-76460 authentication bypass in Identity Services Engine is actively exploited, granting unauthenticated attackers root command execution.
- · 1d agoCVE-2026-76460: Cisco ISE Flaw Actively Exploited
SOCRadar· 80
CVE-2026-76460, a critical flaw in Cisco Identity Services Engine and ISE-PIC, is being actively exploited in the wild.
- · 1d agoCisco security advisory (AV26-932)
Canadian Centre for Cyber Security· 72
Cisco September 2026 updates fix flaws in ASA, FTD, FMC, ISE, and Nexus Dashboard; CISA added actively exploited CVE-2026-76460 to KEV.
- · 19h agoCisco alerts customers to second actively exploited zero-day in as many days
CyberScoop· 88
Cisco confirmed active exploitation of CVE-2026-76460, a CVSS 10.0 ISE API authentication bypass granting root, its second zero-day patch this week.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20281 | Unauthenticated Root RCE via API Injection in Cisco ISE and ISE-PIC CVE-2025-20281 is an injection flaw (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to that API; no valid credentials or user interaction are required. A successful exploit yields arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device (scope-changing per the CVSS 10.0 score). Any organization running affected ISE or ISE-PIC releases is exposed, particularly where the vulnerable API is reachable from untrusted networks. The flaw is confirmed under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-28, EPSS assigns a 97.1% probability of exploitation within 30 days, and ZDI has published a writeup of the unauthenticated root RCE. Do: Upgrade Cisco ISE and ISE-PIC to the patched releases specified in Cisco's PSIRT advisory, and check whether the vulnerable API/admin interface is reachable from untrusted networks, restricting access until patching is complete. As a KEV entry added 2025-07-28, U.S. federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product; given EPSS of 97.1% and confirmed active exploitation, prioritize internet-facing ISE instances and review API/web-server logs for signs of exploitation. | 10.0 | 97% | KEV PoC |
| largeroughly tens of thousands of enterprise/government deployments worldwide (estimate), with an unknown subset exposing the vulnerable API to untrusted networks | |
| CVE-2025-20337 | Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known. Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline. | 10.0 | 68% | KEV |
| moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts) | |
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV PoC |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces | |
| CVE-2026-76461 | Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent. Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts. | 9.8 | 2% | KEV PoC ×3 |
| large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances) |