Cisco has disclosed a critical authentication bypass affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-76460, the vulnerability allows an unauthenticated, remote attacker to send a crafted request to an affected API endpoint and bypass the web-based management interface. The vulnerability received the highest possible CVSS v3.1 score of 10.0. Cisco has confirmed active exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog on September 16, 2026.
Successful exploitation can go well beyond unauthorized access to the management interface. Cisco warns that attackers may obtain command execution with root privileges. That level of access could give an attacker broad control over an affected device and allow them to hide or remove evidence of compromise.
According to Bitsight Threat Intelligence
Bitsight Threat Intelligence gives CVE-2026-76460 a Dynamic Vulnerability Exploit (DVE) score of 10.0 out of 10 and flags it as exploited in the wild. DVE predicts the likelihood of exploitation over the next 90 days. Cisco’s confirmation and the CISA KEV listing provide further evidence that exploitation is already occurring.
CVE-2026-76460 technical overview
Attribute | Details |
|---|---|
| Vulnerability | CVE-2026-76460 |
| Incident type | Authentication bypass under active exploitation |
| Affected products | Cisco ISE and Cisco ISE-PIC, regardless of device configuration |
| Attack requirements | Remote network access, low complexity, no privileges, and no user interaction |
| CVSS v3.1 score | 10.0 (Critical) |
| Potential impact | Unauthorized device access and command execution with root privileges |
| First fixed releases | Cisco lists the first fixed releases as 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco ISE 3.0 has reached the end of software maintenance and should be migrated to a supported fixed release. Cisco also notes that release 3.4 is the last supported release for ISE-PIC |
| Workaround | None |
| Temporary mitigation | Restrict management and control-plane traffic with infrastructure access control lists |
| Exploitation status | Active exploitation confirmed by Cisco; listed in CISA KEV |
Why this matters
Cisco ISE sits at the center of many organizations’ identity and network-access environments. It helps determine which users and devices can connect to a network and what they can access after connecting. Root-level access to that infrastructure can create visibility, integrity, and availability risks across a much wider environment. The vulnerability affects Cisco ISE and ISE-PIC regardless of configuration. It does not require credentials or user interaction, and Cisco has not provided a workaround. Organizations should not assume that a system is safe simply because it is not configured in a particular way or because its logs appear clean. Cisco specifically warns that attackers with root access may remove or conceal evidence. This makes external network and firewall telemetry especially important during an investigation.