Cisco confirms CVE-2026-76460 in ISE
Cisco disclosed an auth bypass in ISE and ISE-PIC with active exploitation and no workaround. Patches are required for 3.1 to 3.5.
Cisco issued a security advisory for CVE-2026-76460, an authentication bypass in Cisco Identity Services Engine and ISE-PIC that can grant unauthorized device access. The company said there are no workarounds and that remediation requires installing software updates, while CISA added the flaw to its exploited-vulnerability catalog.
Cisco published a security advisory for CVE-2026-76460, an authentication bypass vulnerability in Cisco Identity Services Engine and Cisco ISE Passive Identity Connector that allows a remote unauthenticated attacker to bypass authentication and gain unauthorized access to the device. CISA added it to its Known Exploited Vulnerabilities catalog, confirming active exploitation in that record.
What flaw did Cisco fix?
Cisco said the issue sits in a REST API endpoint with insufficient authentication controls. According to the official advisory, an attacker can send specially crafted requests to that API and completely bypass the web administration interface's authentication.
The company also said the vulnerability affects Cisco ISE and ISE-PIC regardless of device configuration. Cisco added that there are no workarounds, and that the only mitigation is to install the corrected software updates.
How severe is it, and which versions are covered?
Independent coverage rated it CVSS 10.0 and said it is an actively exploited flaw that was being used before patches were publicly available. BleepingComputer reported that the fixed versions are Cisco ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
| Data | Detail | Source |
|---|---|---|
| CVE | CVE-2026-76460 | Cisco, CISA |
| Affected product | Cisco ISE, Cisco ISE-PIC | Cisco, BleepingComputer |
| Severity | CVSS 10.0 | Infosecurity Magazine |
| Status | Active exploitation | CISA, Infosecurity Magazine |
| Fixed versions | 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4 | BleepingComputer |
The Hacker News reported that CISA added CVE-2026-76460 to the KEV on Sept. 16, 2026, and that the patch is mandatory for FCEB agencies by Sept. 19, 2026. In parallel, a security awareness post said that using infrastructure access control lists, or iACLs, to restrict access to the ISE management interface can reduce the attack surface while recommended patches are applied, although it does not replace remediation.
What other scenarios do the analyses describe?
An independent technical analysis attributed to Ionix says, on an unconfirmed basis, that exploiting CVE-2026-76460 could lead to root-level command execution on the underlying ISE appliance system. If that happened, the compromise would reach the full platform and could make it easier to delete or alter forensic traces.
CyberPress added that in certain scenarios, exploitation allows unauthenticated attackers to escalate to root command execution on the affected device. Yahoo Tech, meanwhile, placed this CVE within a broader set of at least nine vulnerabilities associated with Cisco ISE, expanding the exposure context around Cisco's identity surface.
Sources
- CVE-2026-76460 – Critical Authentication Bypass – Cisco ISEionix.io· Ionix
- Cisco warns of max severity ISE zero-day exploited in attacksbleepingcomputer.com· BleepingComputer
- The Gatekeeper Is the Door: Cisco ISE's Nine-CVE Disclosure and the Identity Infrastructure Attack Surfacetech.yahoo.com· Yahoo Tech / artículo sindicado
- Cisco ISE Zero-Day Under Active Attack, Gyazo's 23.6M-Record ...rodtrent.substack.com· Rod Trent (Substack)
- Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Accesscyberpress.org· CyberPress
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacksthehackernews.com· The Hacker News
- Cisco Identity Services Engine Authentication Bypass Vulnerabilitycisco.com· Cisco
- Cisco Warns of Active Exploitation of Critical ISE Flawinfosecurity-magazine.com· Infosecurity Magazine
- CVE-2026-76460: Cisco ISE Zero-Day Exploitedsocprime.com· SOC Prime
- Known Exploited Vulnerabilities Catalogcisa.gov· CISA



