Cisco ISE zero-day with CVSS 10.0 rating is under active exploitation

Cisco has confirmed active exploitation of a maximum-severity vulnerability in Cisco Identity Services Engine that can allow an unauthenticated remote attacker to bypass authentication on affected systems.

The flaw, tracked as CVE-2026-76460, carries a CVSS base score of 10.0. Cisco published fixed software on September 16, 2026 and said there are no workarounds that address the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency added the issue to its Known Exploited Vulnerabilities catalog the same day, based on evidence of active exploitation.

For affected organizations, this is an emergency change issue rather than a normal maintenance item. Cisco ISE often sits close to identity, device access, and network policy decisions, which makes unauthorized access to the platform a serious operational risk.

Cisco says the flaw affects ISE and ISE-PIC

According to Cisco, CVE-2026-76460 affects Cisco ISE and Cisco ISE Passive Identity Connector, also known as ISE-PIC, regardless of device configuration. The vulnerability is in an API endpoint with insufficient authentication control.

A remote attacker could exploit the issue by sending a crafted request to the affected API endpoint. Cisco says a successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Cisco also warns that after successful exploitation, threat actors may obtain command execution with root privileges. That raises the response stakes because attackers with that level of access may be able to remove or hide evidence of compromise.

Fixed Cisco ISE releases

Cisco lists the following fixed releases for CVE-2026-76460. Organizations running affected ISE or ISE-PIC releases should validate exposure against Cisco’s advisory and move to the appropriate fixed release.

Cisco ISE or ISE-PIC releaseFirst fixed release
3.13.1 Patch 12
3.23.2 Patch 11
3.33.3 Patch 12
3.43.4 Patch 7
3.53.5 Patch 4

Cisco also notes that Cisco ISE Software Release 3.0 has reached end of software maintenance. Customers on that release are advised by Cisco to migrate to a supported release that includes the fix.

No workaround, but Cisco lists a temporary mitigation

Cisco’s advisory is clear that there are no workarounds that address CVE-2026-76460. That distinction matters. A mitigation may reduce exposure, but it is not a replacement for a fixed release.

As a temporary mitigation, Cisco says organizations can use infrastructure access control lists to allow only required management and control plane traffic destined to the affected device. The purpose is to prevent remote exploitation by restricting which systems can reach the affected management surface.

That mitigation should not be treated as final remediation. Cisco says mitigations are temporary until an upgrade to fixed software is available, and fixed software is already available for supported release lines.

What affected organizations should do now

Affected organizations should treat CVE-2026-76460 as an active incident-response priority until systems are patched and checked for signs of compromise. The minimum operational path is straightforward.

  1. Identify all Cisco ISE and ISE-PIC deployments. Include distributed deployments and any systems that may not appear in the primary asset inventory.
  2. Confirm the running release and patch level. Compare each deployment against Cisco’s fixed release table for CVE-2026-76460.
  3. Upgrade to the appropriate fixed release. Cisco lists 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4 as the first fixed releases.
  4. Restrict management and control plane access while patching is in progress. Cisco’s listed mitigation is to use infrastructure access control lists for required traffic only.
  5. Review logs on every node. Cisco says distributed deployments require log review on each node, not only on the primary system.
  6. Check logs outside the affected appliance. Because Cisco warns that attackers may hide or remove local evidence after root-level access, firewall and network logs should be reviewed for suspicious uploads, downloads, and unexpected connections.
  7. Re-image suspected compromised nodes. Cisco strongly recommends re-imaging affected nodes and restoring from configuration backup if malicious activity is suspected.

Cisco specifically points administrators to the access.log file and says suspicious usernames may indicate attempted exploitation. Cisco’s example command is:

admin#show logging application ise-kong/access.log | include dummyuser

Cisco also says additional access logs can be reviewed by collecting a support bundle with debug logs selected, using shared key encryption, and checking the decrypted bundle for API gateway access logs.

CISA added CVE-2026-76460 to KEV

CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog on September 16, 2026. CISA’s public alert said the additions were based on evidence of active exploitation.

Under CISA’s BOD 26-04 process, Federal Civilian Executive Branch agencies are required to prioritize rapid remediation of certain high-risk KEV-listed vulnerabilities. Public KEV tracking records list a September 19, 2026 remediation date for CVE-2026-76460. CISA also says that although the directive applies to federal civilian agencies, it encourages all organizations to adopt risk-based vulnerability management and prioritize KEV-listed issues.

Why this is more than another patch notice

CVE-2026-76460 combines several risk signals that security and IT teams usually treat as urgent: active exploitation, no full workaround, unauthenticated remote access, a CVSS 10.0 rating, and possible root-level command execution after exploitation.

The exposure also involves a product category that can influence user, device, and network access decisions. That does not mean every affected deployment is internet-exposed or already compromised. It does mean affected organizations should avoid waiting for the next routine patch cycle.

The safest operational decision is to upgrade affected Cisco ISE and ISE-PIC systems to fixed releases, restrict access while that work is underway, and check for evidence of compromise before considering the issue closed.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email