CVE-2026-76460: A critical Cisco ISE authentication bypass under active exploitation

mse major security alert blog
emma-stevens-bio-portrait
Written by Emma Stevens
Senior Threat Intelligence Advisor

Cisco has disclosed a critical authentication bypass affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-76460, the vulnerability allows an unauthenticated, remote attacker to send a crafted request to an affected API endpoint and bypass the web-based management interface. The vulnerability received the highest possible CVSS v3.1 score of 10.0. Cisco has confirmed active exploitation, and CISA  added it to the Known Exploited Vulnerabilities catalog on September 16, 2026.

Successful exploitation can go well beyond unauthorized access to the management interface. Cisco warns that attackers may obtain command execution with root privileges. That level of access could give an attacker broad control over an affected device and allow them to hide or remove evidence of compromise.

According to Bitsight Threat Intelligence

Bitsight Threat Intelligence gives CVE-2026-76460 a Dynamic Vulnerability Exploit (DVE) score of 10.0 out of 10 and flags it as exploited in the wild. DVE predicts the likelihood of exploitation over the next 90 days. Cisco’s confirmation and the CISA KEV listing provide further evidence that exploitation is already occurring.

CVE-2026-76460 technical overview

Attribute

Details

VulnerabilityCVE-2026-76460
Incident typeAuthentication bypass under active exploitation
Affected productsCisco ISE and Cisco ISE-PIC, regardless of device configuration
Attack requirementsRemote network access, low complexity, no privileges, and no user interaction
CVSS v3.1 score10.0 (Critical)
Potential impactUnauthorized device access and command execution with root privileges
First fixed releasesCisco lists the first fixed releases as 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco ISE 3.0 has reached the end of software maintenance and should be migrated to a supported fixed release. Cisco also notes that release 3.4 is the last supported release for ISE-PIC 
WorkaroundNone
Temporary mitigationRestrict management and control-plane traffic with infrastructure access control lists
Exploitation statusActive exploitation confirmed by Cisco; listed in CISA KEV

Why this matters

Cisco ISE sits at the center of many organizations’ identity and network-access environments. It helps determine which users and devices can connect to a network and what they can access after connecting. Root-level access to that infrastructure can create visibility, integrity, and availability risks across a much wider environment. The vulnerability affects Cisco ISE and ISE-PIC regardless of configuration. It does not require credentials or user interaction, and  Cisco has not provided a workaround. Organizations should not assume that a system is safe simply because it is not configured in a particular way or because its logs appear clean. Cisco specifically warns that attackers with root access may remove or conceal evidence. This makes external network and firewall telemetry especially important during an investigation.

CVE-2026-76460 impact to organizations

Organizations running affected Cisco ISE or ISE-PIC releases face serious risks, including:

  • Unauthorized access to the web-based management interface
  • Command execution with root privileges
  • Changes to device settings or network-access controls
  • Exposure of sensitive configuration or operational information
  • Removal or concealment of evidence in device logs
  • Disruption to identity and network-access services
  • Third-party and supply chain exposure when affected systems are operated by vendors or service providers

Recommendations

1. Patch every affected node

Upgrade Cisco ISE and ISE-PIC to the appropriate fixed release: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4. Cisco ISE 3.0 has reached the end of software maintenance, so organizations using it should migrate to a supported release that contains the fix.

2. Restrict management access during remediation

Cisco has not provided a workaround. As a temporary mitigation, use infrastructure access control lists to allow only required management and control-plane traffic to affected devices. This does not replace patching.

3. Review logs on every node

Review ise-kong/access.log for suspicious usernames across every node in the deployment. Cisco uses dummyuser as one non-exhaustive example of a suspicious entry. Additional API gateway access logs can be collected through a support bundle with debug logs included.

4. Check external network and firewall telemetry

Do not rely only on logs stored on the affected device. Cross-check network and firewall logs for unusual activity, including unexpected uploads from an ISE system to external IP addresses or downloads from malicious infrastructure.

5. Re-image systems when compromise is suspected

If malicious activity is suspected, Cisco strongly recommends re-imaging affected nodes and restoring from a configuration backup if needed. Teams should also review administrative accounts, credentials, access policies, and downstream activity that may have been affected.

6. Assess third-party exposure

Identify vendors that operate Cisco ISE, manage network access, or maintain trusted connectivity into your environment. Ask which release they are running, when every node was patched, which logs were reviewed, and whether they found evidence of unauthorized activity. If compromise is suspected, confirm whether the affected systems were re-imaged and what external telemetry was examined.

Threat landscape & context

CVE-2026-76460 follows a familiar pattern: attackers target security and access infrastructure because compromising one control point can create a path into a much larger environment. Systems that manage identity, authentication, and network access are especially valuable because they sit close to trusted connections and sensitive workflows. The confirmed exploitation also shows why a lack of public exploit code should never be treated as evidence of low risk. The risk can also extend beyond systems an organization owns directly. A service provider, systems integrator, or other critical vendor may operate an affected instance or use it to support services delivered to customers. That creates a third-party risk question as well as an internal vulnerability management issue.

How Bitsight CTI and TPRM support you

Threat monitoring: Bitsight Threat Intelligence can track changes in exploit activity, attacker interest, underground discussion, and other signals as the threat evolves.

Vulnerability prioritization: DVE adds a forward-looking view of exploitation likelihood to the CVSS score, helping teams focus on vulnerabilities attackers are most likely to use.

External exposure detection: Bitsight Continuous Monitoring can use externally observable data to help identify and prioritize vendors with relevant exposure, support outreach for critical vulnerabilities, and track responses and remediation over time.

Supply chain exposure management: Bitsight Beacon provides deeper monitoring for critical vendors across pre-incident exposure, active intrusion, and post-compromise evidence. Alerts are validated and enriched with supporting evidence and remediation guidance, then delivered into existing security workflows.

Vendor response and remediation: Beacon’s optional managed services can support vendor notification, evidence sharing, SLA tracking, and escalation through resolution.

Conclusion

CVE-2026-76460 requires immediate attention. It can be exploited remotely without credentials or user interaction, carries a CVSS score of 10.0, and is already being used in real-world attacks. Cisco’s warning that attackers may gain root-level command execution also means clean device logs cannot rule out compromise. Organizations should patch every affected Cisco ISE and ISE-PIC node, review both device and external network logs, and re-image systems when compromise is suspected. That same urgency should extend to critical vendors that operate or manage the technology

Bitsight cta background color
2026 gartner magic quadrant cover

Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies

Get the report and see why Bitsight was named a Visionary.

 

Download

Bitsight cta background color