Cybersecurity | Published September 21, 2026 | Source: The Hacker News / CISA
Cisco disclosed CVE-2026-76460 on September 16, an authentication bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that received the maximum possible CVSS severity score of 10.0. Cisco's Product Security Incident Response Team confirmed the flaw is being actively exploited in the wild.
What the Vulnerability Does
The issue stems from insufficient authentication control on a management API endpoint. An unauthenticated, remote attacker can send a single crafted request to bypass Cisco ISE's web-based management interface entirely — no valid credentials required — and potentially achieve root-level command execution on the affected appliance.
Cisco ISE is widely deployed as a central identity and network-access control platform, meaning a compromised ISE instance can give an attacker visibility and control over policy decisions across an organization's entire network segmentation strategy.
Who's Affected
The vulnerability affects Cisco ISE and ISE-PIC versions 3.0 through 3.5, regardless of deployment configuration. Cisco has released fixed versions (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4), and version 3.0 has reached end of software maintenance, meaning organizations still running it need to migrate to a supported release entirely.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on the same day it was disclosed, giving federal agencies until September 19 to remediate — an unusually tight turnaround that signals how seriously the vulnerability is being treated.
What to Do
Cisco has stated there is no software workaround for this vulnerability. Organizations running affected ISE deployments should patch immediately, and in the meantime can use infrastructure access control lists (iACLs) to restrict management-plane traffic as a temporary, partial mitigation. Given the flaw was already under active exploitation before public disclosure, security teams should also review logs for signs of prior compromise, not just apply the patch and move on.
This summary is based on reporting from The Hacker News, Help Net Security, and Cisco's own security advisory. For complete technical indicators of compromise, refer to Cisco's official advisory.
