Cisco Patches Actively Exploited Maximum-Severity Identity Services Engine Vulnerability
Cisco has released security updates for a maximum-severity vulnerability in its Identity Services Engine (ISE) that attackers are actively exploiting.
Cisco ISE is a centralized policy platform that IT administrators use to manage access to network resources for endpoints, users, and devices. It is often used to enforce a Zero Trust security model.
Cisco ISE authentication bypass vulnerability
Tracked as CVE-2026-76460, the flaw affects the APIs of Cisco Identity Services Engine and Cisco ISE Passive Identity Connector (ISE-PIC). Remote attackers can exploit the vulnerability to bypass authentication regardless of the affected system’s configuration.
“This vulnerability is due to insufficient authentication controls on the API endpoint. An attacker could exploit this vulnerability by sending crafted requests to an affected API endpoint,” Cisco explained.
“A successful exploit could allow the attacker to bypass the web-based management interface and gain unauthorized access to an affected device.”
Cisco warned customers on Wednesday to protect their systems after the company’s Product Security Incident Response Team (PSIRT) confirmed that CVE-2026-76460 was being actively exploited.
“Cisco PSIRT is aware that this vulnerability is being actively exploited. Cisco strongly recommends that customers upgrade to a fixed software release that fixes this vulnerability.”
There is no workaround for the flaw. Cisco recommends applying the security updates as the only measure available to protect affected networks from ongoing attacks.
Cisco ISE fixed versions
Administrators should upgrade to the following Cisco ISE or ISE-PIC releases:
| Cisco ISE or ISE-PIC release | First fixed release |
|---|---|
| 3.1 | 3.1 patch 12 |
| 3.2 | 3.2 patch 11 |
| 3.3 | 3.3 patch 12 |
| 3.4 | 3.4 patch 7 |
| 3.5 | 3.5 patch 4 |
Cisco shares indicators of compromise
Cisco shared indicators of compromise and advised security teams to check the access.log file on all nodes for suspicious usernames.
If malicious activity is suspected, Cisco “strongly” recommends reimaging affected nodes and restoring them from backups.
Administrators should also review firewall and network logs for suspicious activity, including downloads and uploads to or from external or malicious IP addresses. Attackers may remove evidence of exploitation after executing commands with root privileges.
More critical Cisco ISE vulnerabilities disclosed
Cisco also recently patched a second maximum-severity authentication bypass vulnerability, tracked as CVE-2026-76423.
Five other critical security issues affecting Cisco ISE and Cisco ISE-PIC are tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284. The other listed vulnerabilities have not yet been flagged as actively exploited.
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday and ordered federal agencies to patch their systems within three days of applying the patch. The agency’s alert provides additional details.
In July 2025, attackers exploited another Cisco ISE zero-day, CVE-2025-20337, in remote code execution attacks. The attackers deployed a custom “IdentityAuditAction” web shell that masqueraded as a legitimate ISE component.
Over the past five years, CISA has listed 99 Cisco product vulnerabilities as actively exploited, including seven used in ransomware attacks.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



