Cisco has shipped an emergency patch and public advisory for CVE-2026-76460, a maximum-severity authentication bypass in its Identity Services Engine (ISE) that is being actively exploited. The CVSS 10.0 flaw, disclosed on September 17, 2026, lets a remote unauthenticated attacker send a crafted API request and gain root-level command execution on the appliance.
An API endpoint with no auth
Cisco says the vulnerability stems from "insufficient authentication control on an API endpoint" in ISE's web-based management interface. A successful attack bypasses login entirely, giving intruders the ability to run arbitrary commands as root — and, once inside, "remove evidence of compromise". Both Cisco ISE and the ISE Passive Identity Connector (ISE-PIC) are affected.
The company first learned of the flaw through a support ticket where the abuse pattern was already visible, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 16.
Patches by ISE release train
Cisco's advisory lists fixed builds across the currently supported ISE trains:
- ISE 3.1 — Patch 12
- ISE 3.2 — Patch 11
- ISE 3.3 — Patch 12
- ISE 3.4 — Patch 7
- ISE 3.5 — Patch 4
There is no viable workaround, so administrators are being told to update immediately, restrict the management interface to trusted networks, and audit ISE hosts for signs of prior compromise — including logs erased by attackers.
Cisco's second maximum-severity ISE hit this year
The disclosure lands only weeks after another critical RCE in Cisco's Nexus 9000 switching gear, and against a backdrop of AI-assisted attackers moving faster than defenders can patch. Recent reports from GreyNoise and Anthropic highlight how quickly threat actors are wiring LLMs into exploitation pipelines.
Enterprise identity is now high-value real estate
ISE sits at the front door of many enterprise networks, handling 802.1X, TACACS+ and network access control. That makes CVE-2026-76460 particularly valuable — a foothold there is a gateway to VLAN pivoting, credential harvesting and lateral movement. Cisco confirmed the flaw is being weaponised now, so treating this as a same-day patch is the safest posture.
Reporting based on coverage from Cisco, The Hacker News, SecurityWeek and CybersecurityNews.
