Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Source: Help Net Security

Author: Zeljka Zorz

URL: https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/

ONE SENTENCE SUMMARY:

Cisco warns CVE-2026-76460 actively exploits Cisco ISE API authentication bypass; update, hunt indicators, and reimage compromised nodes.

MAIN POINTS:

  1. Cisco confirmed active exploitation of CVE-2026-76460 in Cisco Identity Services Engine.
  2. Vulnerability is an authentication bypass caused by insufficient API endpoint authentication controls.
  3. Remote unauthenticated attackers can bypass the web management interface via crafted requests.
  4. Affected products include Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC).
  5. Impacted versions span releases 3.0 through 3.5 across deployments.
  6. Cisco provided indicators of compromise but withheld observed attack details.
  7. Investigation should review access.log for suspicious usernames on every node.
  8. If compromise suspected, re-image affected nodes and restore configurations from backups.
  9. Verify external firewall and network logs for suspicious uploads/downloads tied to affected devices.
  10. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.

TAKEAWAYS:

  1. Patch immediately because no workaround mitigates this actively exploited authentication bypass.
  2. Treat all cluster nodes as potentially affected and perform uniform log review.
  3. Preserve evidence by correlating device activity with external network and firewall telemetry.
  4. Plan migration away from 3.0–3.2 due to limited or ended maintenance support.
  5. Expect additional ISE/ISE-PIC security fixes, including findings from researchers and internal AI-assisted testing.