Cisco has issued emergency security updates for a critical vulnerability in its Identity Services Engine (ISE) after confirming that the flaw is being actively exploited in the wild.
Tracked as CVE-2026-76460 and rated 10.0 on the CVSS severity scale, the vulnerability allows remote, unauthenticated attackers to bypass authentication by sending specially crafted requests to an affected API endpoint.
Critical Authentication Bypass Vulnerability
According to Cisco, the flaw exists because an API endpoint in ISE does not properly enforce authentication controls. Attackers can exploit the weakness to bypass the appliance’s web-based management interface and gain unauthorized access.
The vulnerability affects both Cisco ISE and ISE Passive Identity Connector (ISE-PIC), regardless of the configuration in use.
Cisco said there is currently no software workaround for the vulnerability. However, organizations can use infrastructure access control lists (iACLs) to restrict network traffic to affected systems and reduce the risk of remote exploitation.
Cisco Urges Customers to Install Fixed Versions
Cisco strongly recommends that customers upgrade to a patched software release as soon as possible.
The affected products can be secured by installing the following versions:
- ISE and ISE-PIC 3.5 Patch 4
- ISE and ISE-PIC 3.4 Patch 7
- ISE and ISE-PIC 3.3 Patch 12
- ISE and ISE-PIC 3.2 Patch 11
- ISE and ISE-PIC 3.1 Patch 12
Cisco’s Product Security Incident Response Team (PSIRT) confirmed that exploitation is already occurring and urged customers to prioritize the security updates.
Organizations Advised to Check for Compromise
Because the vulnerability is being exploited, administrators are also advised to investigate their ISE deployments for signs of unauthorized activity.
Cisco recommends reviewing the access.log file on every node for suspicious usernames or other unusual entries. In distributed environments, each individual node should be examined.
If evidence of malicious activity is discovered, Cisco recommends re-imaging affected nodes and restoring them from a known-good configuration backup where necessary.
Attackers Could Gain Root-Level Access
Cisco warns that successful exploitation could allow an attacker to execute commands with root privileges on the affected system.
Such access could give attackers the ability to modify or remove evidence of their activity, including indicators of compromise (IoCs), potentially making post-incident investigation more difficult.
Administrators should therefore examine network and firewall logs outside the affected ISE appliance for suspicious activity. Unexpected file uploads, downloads or other unusual connections may provide additional evidence of compromise.
CISA Adds Vulnerability to Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, reflecting confirmed exploitation of the security flaw.
Cisco has not identified the threat actor or group responsible for the attacks. The company noted that vulnerabilities in its networking and security products are frequently targeted by both cybercriminals and state-sponsored threat actors.
Organizations running Cisco ISE or ISE-PIC should prioritize applying the available patches and conduct appropriate log reviews to determine whether their environments have already been targeted.