Source: Help Net Security
Author: Zeljka Zorz
URL: https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/
ONE SENTENCE SUMMARY:
Cisco warns CVE-2026-76460 actively exploits Cisco ISE API authentication bypass; update, hunt indicators, and reimage compromised nodes.
MAIN POINTS:
- Cisco confirmed active exploitation of CVE-2026-76460 in Cisco Identity Services Engine.
- Vulnerability is an authentication bypass caused by insufficient API endpoint authentication controls.
- Remote unauthenticated attackers can bypass the web management interface via crafted requests.
- Affected products include Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC).
- Impacted versions span releases 3.0 through 3.5 across deployments.
- Cisco provided indicators of compromise but withheld observed attack details.
- Investigation should review access.log for suspicious usernames on every node.
- If compromise suspected, re-image affected nodes and restore configurations from backups.
- Verify external firewall and network logs for suspicious uploads/downloads tied to affected devices.
- Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.
TAKEAWAYS:
- Patch immediately because no workaround mitigates this actively exploited authentication bypass.
- Treat all cluster nodes as potentially affected and perform uniform log review.
- Preserve evidence by correlating device activity with external network and firewall telemetry.
- Plan migration away from 3.0–3.2 due to limited or ended maintenance support.
- Expect additional ISE/ISE-PIC security fixes, including findings from researchers and internal AI-assisted testing.