Connect with us

Cybersecurity

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Published

on

Cisco has released emergency security updates for a critical vulnerability in its Identity Services Engine (ISE) after confirming that the flaw is being actively exploited in the wild.

Tracked as CVE-2026-76460 and carrying a CVSS score of 10.0, the vulnerability is an authentication bypass affecting an API endpoint. Remote, unauthenticated attackers can exploit the weakness using specially crafted requests to gain access to the affected system.

Critical Cisco ISE Authentication Bypass

The vulnerability exists because the affected API endpoint does not enforce sufficient authentication controls.

An attacker can send a specially crafted request to bypass authentication protections and gain access through the web-based management interface. Cisco warns that successful exploitation can ultimately provide attackers with root-level command execution.

The vulnerability affects both Cisco ISE and ISE Passive Identity Connector (ISE-PIC), regardless of the configuration in use.

Cisco has not provided a workaround, but it says organizations can use infrastructure access control lists (iACLs) to restrict network traffic to affected devices and prevent remote exploitation.

Cisco Releases Fixed Software Versions

Cisco recommends that customers upgrade affected systems to one of the following fixed releases:

  • ISE/ISE-PIC 3.5 Patch 4
  • ISE/ISE-PIC 3.4 Patch 7
  • ISE/ISE-PIC 3.3 Patch 12
  • ISE/ISE-PIC 3.2 Patch 11
  • ISE/ISE-PIC 3.1 Patch 12

The company strongly recommends upgrading because the vulnerability is already being exploited by attackers.

Organizations Should Check for Compromise

Because CVE-2026-76460 has been exploited in real-world attacks, Cisco is also advising administrators to investigate their environments for signs of compromise.

Security teams should review the access.log file for unusual usernames or other suspicious entries. In distributed ISE deployments, logs from every individual node should be examined.

Cisco warns that suspicious entries could indicate malicious activity. If compromise is confirmed or strongly suspected, the company recommends re-imaging affected nodes and restoring them from configuration backups where necessary.

Attackers Could Hide Evidence

The ability to execute commands with root privileges significantly increases the potential impact of successful exploitation.

An attacker with root access could potentially modify or remove indicators of compromise (IoCs), making forensic investigation more difficult and allowing malicious activity to remain hidden.

Organizations should therefore look beyond the compromised device when investigating potential attacks. Reviewing external network and firewall logs can help identify suspicious connections, unexpected uploads or downloads and other unusual activity.

CISA Adds Cisco Zero-Day to KEV Catalog

The US Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) Catalog.

The inclusion confirms that the vulnerability meets CISA’s criteria for known exploitation and increases the urgency for affected organizations to apply the available security updates.

Federal agencies are expected to address the vulnerability within the required timeframe under applicable CISA directives.

Immediate Patching Recommended

The combination of a maximum CVSS severity score, remote unauthenticated exploitation and confirmed attacks makes the Cisco ISE vulnerability a significant security concern for organizations using affected versions.

Administrators should identify vulnerable ISE and ISE-PIC installations, apply the appropriate Cisco patches and review security logs for evidence of previous exploitation.

Organizations should also consider restricting access to ISE management interfaces and monitoring network activity around affected systems as part of their incident-response efforts.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2026 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO