
Since September 16, 2026, the critical CVE-2026-76460 vulnerability in Cisco Identity Services Engine (ISE) has become an active zero-day risk for organizations that rely on Cisco ISE or Cisco ISE Passive Identity Connector (ISE-PIC) to enforce identity-aware network access. Cisco rates the flaw at CVSS 10.0, says exploitation is active, and has released fixed software for supported 3.x branches.
The issue is an unauthenticated authentication bypass in an ISE API endpoint. A remote attacker can send crafted requests that bypass the web-based management interface and gain unauthorized access to the affected device. Cisco also warns that successful exploitation may lead to command execution with root privileges, which raises the stakes from management-plane exposure to full appliance compromise.
This is a patch-first incident. There are no workarounds that fully address CVE-2026-76460. Cisco recommends upgrading to the fixed releases, limiting management and control-plane traffic with infrastructure ACLs, and checking every node in distributed deployments for suspicious access.log entries.
CVE-2026-76460 is a critical-severity authentication bypass vulnerability (CVSS 10.0) in Cisco ISE and Cisco ISE-PIC. Cisco says the weakness exists because an API endpoint does not apply sufficient authentication controls.
The affected products are:
| Product | Exposure | Configuration dependency |
|---|---|---|
| Cisco Identity Services Engine (ISE) | Affected | None. Cisco says the flaw applies regardless of configuration. |
| Cisco ISE Passive Identity Connector (ISE-PIC) | Affected | None. Cisco says the flaw applies regardless of configuration. |
The risk is especially serious because ISE sits close to enterprise identity and access management, network admission, device posture, and policy enforcement. A compromise of that management plane can give attackers a privileged vantage point into access policy and connected infrastructure.
Cisco provided a non-exhaustive example for checking for suspicious usernames in access.log:
admin#show logging application ise-kong/access.log | include dummyuser
For distributed deployments, defenders should run log review across every node, not only the primary administrative node. Cisco also recommends collecting support bundles with debug logs when additional access.log files are needed.
The patch, released in Cisco's September 16, 2026 advisory set, addresses the authentication bypass in the affected API. However, because Cisco has confirmed active exploitation and CISA added the CVE to the Known Exploited Vulnerabilities catalog, organizations should treat delayed patching as active exposure.
| Date | Event | Status |
|---|---|---|
| September 16, 2026 | Cisco publishes the advisory for CVE-2026-76460 and releases fixed software. | Patch available |
| September 16, 2026 | Cisco PSIRT confirms awareness of active exploitation. | Active exploitation |
| September 16, 2026 | CISA adds CVE-2026-76460 to the KEV catalog. | Federal remediation clock starts |
| September 17, 2026 | Independent security media report the zero-day and emergency patch guidance. | Public disclosure expands |
| September 19, 2026 | Federal Civilian Executive Branch agencies face CISA's required remediation deadline. | Mandatory patch deadline |
Cisco has not publicly attributed the exploitation to a named threat actor, campaign, or country-nexus group. That lack of attribution should not reduce urgency: Cisco ISE appliances are high-value management systems, and the vulnerability requires no authentication.
From a defender's perspective, the most important assumption is that exploitation evidence may be incomplete. Cisco warns that root-level access could allow threat actors to remove or hide indicators of compromise. That means local logs are useful, but they should be corroborated with network, firewall, proxy, and file-transfer telemetry outside the ISE appliance.
Cisco ISE is commonly used to make access decisions across wired, wireless, VPN, guest, and device posture workflows. That makes the appliance more than another web console. It can influence who and what is allowed onto sensitive network segments.
This is where access control and network segmentation matter operationally. The faster defenders reduce management access to only required sources, the less room attackers have to reach the vulnerable endpoint.
Upgrade affected deployments to the fixed releases:
| Cisco ISE or ISE-PIC release | First fixed release |
|---|---|
| 3.1 | 3.1 Patch 12 |
| 3.2 | 3.2 Patch 11 |
| 3.3 | 3.3 Patch 12 |
| 3.4 | 3.4 Patch 7 |
| 3.5 | 3.5 Patch 4 |
Cisco ISE 3.0 has reached end of software maintenance, so organizations still running 3.0 should migrate to a supported release that includes the fix.
Cisco says there are no workarounds that address CVE-2026-76460, but it recommends infrastructure access control lists as a mitigation. Limit management and control-plane traffic destined to ISE only to required administrative sources.
Recommended controls:
Cisco recommends reviewing access.log for suspicious usernames on every node. Start with Cisco's example, then broaden the hunt around unusual usernames, unexpected API paths, and abnormal source IPs.
show logging application ise-kong/access.log | include dummyuser
If suspicious activity appears, Cisco recommends re-imaging affected nodes and restoring from configuration backup if needed. Treat this as an incident response workflow rather than a routine patch task.
Because attackers may gain root privileges and hide local evidence, review telemetry that the ISE appliance cannot alter:
Example Splunk hunt for unexpected outbound traffic from ISE nodes:
index=network sourcetype=firewall
src_ip IN ("<ISE_NODE_1>", "<ISE_NODE_2>", "<ISE_NODE_3>")
| where action="allowed"
| stats count min(_time) as first_seen max(_time) as last_seen by src_ip, dest_ip, dest_port, app
| sort - count
Example Microsoft Sentinel query for new source IPs reaching ISE management services:
CommonSecurityLog
| where DestinationIP in ("<ISE_NODE_1>", "<ISE_NODE_2>", "<ISE_NODE_3>")
| where DestinationPort in (443, 8443, 9060)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Count=count() by SourceIP, DestinationIP, DestinationPort
| order by FirstSeen desc
Cisco has not published a broad IoC list for this issue. The most concrete hunting guidance is behavioral and log-based:
| Signal | Why it matters | Where to check |
|---|---|---|
Suspicious usernames in access.log | Cisco's primary exploitation check | Every ISE and ISE-PIC node |
| Unexpected uploads from ISE | Possible data staging or exfiltration | Firewall, proxy, NetFlow |
| Downloads from malicious or unfamiliar IPs | Possible tooling or payload retrieval | Firewall, DNS, proxy |
| Missing or altered local evidence | Possible root-level cleanup | Compare local logs with external telemetry |
If exploitation is suspected, preserve evidence before re-imaging where possible, but do not leave an actively compromised ISE node in service longer than necessary. Prioritize containment, clean rebuilds, backup validation, and credential review for connected administrative integrations.
CVE-2026-76460 is a live Cisco ISE zero-day with maximum severity, no full workaround, and potential root-level impact.
Move this to the front of the patch queue. If Cisco ISE helps decide who gets onto your network, a zero-day in that control point deserves same-day action, not a routine maintenance window.
CVE-2026-76460 is a critical Cisco ISE and Cisco ISE-PIC authentication bypass vulnerability with a CVSS score of 10.0. Cisco says an unauthenticated remote attacker can exploit the vulnerable API endpoint with crafted requests.
Yes. Cisco PSIRT says it is aware of active exploitation, and CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, 2026.
Cisco lists the first fixed releases as ISE or ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco ISE 3.0 is end of software maintenance and should be migrated to a supported fixed release.
No full workaround is available. Cisco recommends using infrastructure access control lists to restrict management and control-plane traffic to affected devices as a mitigation until fixed software is applied.
Review access.log for suspicious usernames on every ISE node, cross-check firewall and network logs for unexpected uploads or downloads, and investigate any unusual management access before and after patching.
Cisco ISE often enforces identity-aware network access policies. A compromise can expose a high-trust control point tied to authentication, device access, policy enforcement, and administrative integrations.
Lucas Oliveira. CVE-2026-76460: Cisco ISE Auth Bypass Zero-Day. 18 Sept 2026. Invaders Cybersecurity. https://invaders.ie/resources/blog/vulnerability/cve-2026-76460-cisco-ise-auth-bypass-zero-day.
Subscribe via RSS.
Written by
Research
A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.
Get the latest cybersecurity insights delivered to your inbox.