CiberLATAMbywhalemate

Cisco confirms CVE-2026-76460 in ISE

Cisco disclosed an auth bypass in ISE and ISE-PIC with active exploitation and no workaround. Patches are required for 3.1 to 3.5.

Whalemate Labs · AI-assisted researchPublished:2 min read

Cisco issued a security advisory for CVE-2026-76460, an authentication bypass in Cisco Identity Services Engine and ISE-PIC that can grant unauthorized device access. The company said there are no workarounds and that remediation requires installing software updates, while CISA added the flaw to its exploited-vulnerability catalog.

Cisco published a security advisory for CVE-2026-76460, an authentication bypass vulnerability in Cisco Identity Services Engine and Cisco ISE Passive Identity Connector that allows a remote unauthenticated attacker to bypass authentication and gain unauthorized access to the device. CISA added it to its Known Exploited Vulnerabilities catalog, confirming active exploitation in that record.

What flaw did Cisco fix?

Cisco said the issue sits in a REST API endpoint with insufficient authentication controls. According to the official advisory, an attacker can send specially crafted requests to that API and completely bypass the web administration interface's authentication.

The company also said the vulnerability affects Cisco ISE and ISE-PIC regardless of device configuration. Cisco added that there are no workarounds, and that the only mitigation is to install the corrected software updates.

How severe is it, and which versions are covered?

Independent coverage rated it CVSS 10.0 and said it is an actively exploited flaw that was being used before patches were publicly available. BleepingComputer reported that the fixed versions are Cisco ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.

Data Detail Source
CVE CVE-2026-76460 Cisco, CISA
Affected product Cisco ISE, Cisco ISE-PIC Cisco, BleepingComputer
Severity CVSS 10.0 Infosecurity Magazine
Status Active exploitation CISA, Infosecurity Magazine
Fixed versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4 BleepingComputer

The Hacker News reported that CISA added CVE-2026-76460 to the KEV on Sept. 16, 2026, and that the patch is mandatory for FCEB agencies by Sept. 19, 2026. In parallel, a security awareness post said that using infrastructure access control lists, or iACLs, to restrict access to the ISE management interface can reduce the attack surface while recommended patches are applied, although it does not replace remediation.

What other scenarios do the analyses describe?

An independent technical analysis attributed to Ionix says, on an unconfirmed basis, that exploiting CVE-2026-76460 could lead to root-level command execution on the underlying ISE appliance system. If that happened, the compromise would reach the full platform and could make it easier to delete or alter forensic traces.

CyberPress added that in certain scenarios, exploitation allows unauthenticated attackers to escalate to root command execution on the affected device. Yahoo Tech, meanwhile, placed this CVE within a broader set of at least nine vulnerabilities associated with Cisco ISE, expanding the exposure context around Cisco's identity surface.

Sources

View all