
Cisco’s Identity Services Engine sits at the centre of how many organisations control who and what can connect to their networks, and this immediately makes a newly disclosed security flaw very serious.
Cisco has confirmed that attackers are actively exploiting CVE-2026-76460, a critical vulnerability that can let a remote attacker bypass authentication and gain unauthorised access to affected ISE systems.
Disclosed in mid-September, Cisco gave it the maximum CVSS score of 10.0, as it affects Cisco Identity Services Engine and the Cisco ISE Passive Identity Connector, or ISE-PIC, regardless of device configuration. More importantly, the company released patches and says there is no full workaround.
How Attackers Can Bypass the Management Interface
The weakness is in an ISE application programming interface, and according to the company, it exists because of “insufficient authentication control on an API endpoint.”
In this case, an attacker who can reach the vulnerable endpoint can send a specially crafted request and bypass the web-based management interface without needing a valid account or any action from a user.
The risk also does not stop at getting past the login process. Cisco warns that successful exploitation may allow threat actors to execute commands with root privileges, and this level of access means attackers could remove or hide evidence after compromising a device, which may further make investigations more difficult.
Cisco Confirms the Vulnerability Is Being Exploited
Cisco’s Product Security Incident Response Team says it is aware of active exploitation, as the vulnerability was discovered while Cisco was resolving a Technical Assistance Center support case. However, the company has not publicly identified the attackers, disclosed how many organisations have been affected, or said when the attacks began.
The U.S. Cybersecurity and Infrastructure Security Agency also added CVE-2026-76460 to its Known Exploited Vulnerabilities catalogue on September 16. And federal civilian agencies were given until September 19 to follow the required remediation guidance, reflecting how quickly the flaw was treated after disclosure.
The vulnerability was also disclosed as part of a much larger Cisco security update. The company published fixes covering 77 new CVEs on September 16, with 41 affecting ISE alone. Among the ISE flaws were three other vulnerabilities carrying the maximum CVSS score of 10.0 – CVE-2026-20130, CVE-2026-20192, and CVE-2026-76423.
Which Cisco ISE Versions Need to Be Updated
Cisco has fixed the vulnerability in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Customers still running ISE 3.0 are advised to move to a supported release because that version has reached the end of software maintenance.
Although Cisco says there is no workaround that fixes the vulnerability itself, administrators can still reduce exposure by using infrastructure access control lists to limit management and control plane traffic reaching affected systems.
Cisco is also asking administrators to review ISE access logs for suspicious usernames on every node in a deployment. If malicious activity is suspected, the company recommends re-imaging affected nodes and restoring them from a configuration backup. It also advises checking network and firewall logs outside the device because attackers with root access may be able to hide evidence locally.
