Summary
- CVE-2026-76460 is a CVSS 10.0 authentication bypass in Cisco ISE and ISE-PIC, exploitable remotely without credentials or user interaction.
- Successful exploitation grants root privileges and may allow attackers to erase or conceal forensic evidence on the affected appliance.
- CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog; Cisco confirmed active exploitation discovered through a support case.
- No workaround exists; patches are available for ISE versions 3.1 through 3.5, and ISE 3.0 users must migrate to a supported release.
- The disclosure follows a separate actively exploited 9.8-rated flaw in Cisco Secure Email Gateway, making September a heavy patching period for Cisco environments.
A Maximum-Severity Flaw in Network Access Control
Cisco has disclosed CVE-2026-76460, an authentication bypass vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) platforms. The flaw carries a CVSS score of 10.0 — the highest possible — and is already under active exploitation in the wild. Cisco’s Product Security Incident Response Team confirmed awareness of attacks and is urging customers to apply fixes without delay.
How the Vulnerability Works
The flaw resides in an API within ISE, Cisco’s network access control platform. Insufficient authentication controls on that API endpoint mean an attacker can send a specially crafted request to bypass the product’s web-based management interface entirely. No credentials are required, no user interaction is needed, and Cisco states that all vulnerable versions of ISE and ISE-PIC are affected regardless of how they are configured. A successful attacker gains command execution with root privileges.
Evidence Destruction Is a Genuine Risk
The root access this vulnerability provides creates a secondary problem beyond initial compromise. Cisco has warned explicitly that attackers with root-level control may be able to remove or conceal traces of an intrusion, complicating any subsequent investigation into whether an appliance was breached and what was done once inside. This makes early detection and out-of-band log preservation particularly important for affected organisations.
Detection Guidance from Cisco
Cisco has advised administrators to review ISE access logs for suspicious usernames across every node in a distributed deployment. Network and firewall logs held outside the affected device should also be examined for signs of unexpected uploads or downloads. Critically, because the device itself may have been tampered with, logs stored on the appliance cannot be fully trusted if exploitation is suspected.
What to Do If Compromise Is Suspected
Where administrators find evidence of possible exploitation, Cisco strongly recommends reimaging affected nodes and restoring configurations from a known-good backup. There is no software workaround for the vulnerability itself, though Cisco notes that infrastructure access control lists can serve as a temporary mitigation by restricting management and control-plane traffic from reaching affected systems.
Patching Path and Unsupported Versions
Permanent fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Organisations running ISE 3.0 face a harder task: that version has reached the end of software maintenance, meaning no patch will be issued for it and migration to a supported release is required. Cisco discovered the vulnerability while working through a Technical Assistance Center support case, though it has not disclosed who is responsible for the active exploitation, how long attacks have been underway, or what post-compromise activity has occurred.
Part of a Broader Cisco Disclosure Wave
This advisory did not arrive in isolation. The same week saw Cisco disclose CVE-2026-76461, a 9.8-rated flaw affecting its Secure Email Gateway and Secure Email and Web Manager appliances — also under active exploitation and also capable of leading to root access. The Wednesday ISE advisory batch included two additional vulnerabilities scoring 10.0, alongside a separate group of remote code execution flaws rated as high as 9.9. For teams managing Cisco infrastructure, the cumulative patching burden this month is considerable. CISA has added the ISE flaw to its Known Exploited Vulnerabilities catalog, which carries formal remediation obligations for US federal agencies and serves as a meaningful urgency signal for the broader enterprise community.
Why it matters
ISE functions as a trust anchor for network access control — it enforces who and what is allowed onto the network. A root-level compromise of ISE does not just expose the appliance itself; it potentially undermines the integrity of every access policy decision that flows through it. For CISOs, the combination of a perfect CVSS score, confirmed active exploitation, no workaround, and an attacker’s demonstrated ability to cover their tracks means this demands immediate prioritisation. The risk is compounded for organisations on end-of-life ISE 3.0, where the only path forward is a platform migration, not a patch.
What to do now
- Apply the relevant ISE or ISE-PIC patch immediately: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4.
- If running ISE 3.0, begin migration to a supported release as no patch will be made available for that version.
- As a temporary measure where patching is not immediately possible, deploy infrastructure access control lists to restrict management and control-plane traffic reaching ISE systems.
- Review ISE access logs for suspicious usernames across all nodes in any distributed deployment.
- Examine network and firewall logs held outside the affected appliance for signs of unexpected uploads or downloads.
- If evidence of exploitation is found, reimage affected nodes and restore configuration from a known-good backup.
- Ensure log collection from ISE is being forwarded to an external SIEM or log store, given that on-device logs may be unreliable after a root-level compromise.
