CVE-2026-76460
September 17, 2026
·
0
Minutes Read

Cisco Identity Services Engine Authentication Bypass – Actively Exploited

Security Advisory
Advisory
September 17, 2026
·
0
Minutes Read

Cisco Identity Services Engine Authentication Bypass – Actively Exploited

Security Advisory
Advisory
September 17, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Cisco disclosed a critical, unauthenticated authentication bypass vulnerability (CVE-2026-76460, CVSS 3.1 10.0) in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), caused by insufficient authentication control on an API endpoint. Successful exploitation grants an unauthenticated remote attacker unauthorized access to the device's management interface. Cisco PSIRT confirms active exploitation, and CISA has added the CVE to the Known Exploited Vulnerabilities (KEV) catalog with an expedited BOD-26-04 forensic-triage deadline of 2026-09-19. No workaround exists; Cisco has published fixed patch releases.

Affected Systems and/or Applications

Vulnerable: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), all device configurations.

Affected versions and first fixed releases:

<table style="border-collapse: collapse; width: 100%;">
  <thead>
    <tr>
      <th style="border: 1px solid #ddd; padding: 8px; text-align: left;">Version</th>
      <th style="border: 1px solid #ddd; padding: 8px; text-align: left;">First Fixed Release</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.1</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.1 Patch 12</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.2</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.2 Patch 11</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.3</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.3 Patch 12</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.4</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.4 Patch 7</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.5</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.5 Patch 4</td>
    </tr>
  </tbody>
</table>

Technical Details

Vulnerability Mechanism

An API endpoint on Cisco ISE/ISE-PIC has insufficient authentication control, allowing an unauthenticated, remote attacker to bypass authentication and gain unauthorized access to the device's management interface. The flaw is tracked as CWE-648 (Incorrect Use of Privileged APIs).

Observed Exploitation Path

Cisco PSIRT confirms active exploitation of this vulnerability. CISA independently corroborated active/known exploitation by adding CVE-2026-76460 to the KEV catalog on 2026-09-16, with a 2026-09-19 remediation due date and a required action to evaluate internet exposure in addition to applying vendor mitigations.

Key Points

  • CVSS 3.1 base score 10.0 (Critical, maximum score) — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
  • CISA KEV-listed with CWE-648, added 2026-09-16, due 2026-09-19, forensic triage required per BOD-26-04, with an explicit required action to evaluate internet exposure.
  • No workaround is available; the only published mitigation is restricting management-traffic access via infrastructure ACLs.
  • FIRST EPSS has not yet published a probability/percentile score for this CVE as of 2026-09-17.
  • Scanner coverage: Qualys QID 317886 covers this CVE (pipeline status "In QA" as of 2026-09-17, authenticated detection via Cisco ISE version/ise_patch).

Mitigation

Immediate Actions for Self-Hosted Instances

Limit Exposure

Cisco has not published a workaround. Cisco recommends using infrastructure access control lists to restrict management-traffic access to affected devices, and CISA's required action explicitly includes evaluating internet exposure of affected devices.

Patch/Upgrade

Upgrade to the first fixed release for the deployed version:

<table style="border-collapse: collapse; width: 100%;">
  <thead>
    <tr>
      <th style="border: 1px solid #ddd; padding: 8px;">Version</th>
      <th style="border: 1px solid #ddd; padding: 8px;">First Fixed Release</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.1</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.1 Patch 12</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.2</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.2 Patch 11</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.3</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.3 Patch 12</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.4</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.4 Patch 7</td>
    </tr>
    <tr>
      <td style="border: 1px solid #ddd; padding: 8px;">3.5</td>
      <td style="border: 1px solid #ddd; padding: 8px;">3.5 Patch 4</td>
    </tr>
  </tbody>
</table>
<br>

Threat Hunting

Cisco's advisory publishes Indicators of Compromise guidance:

  • Review access.log for suspicious usernames, e.g.: admin#show logging application ise-kong/access.log | include dummyuser
  • Additional access logs can be collected via a support bundle (debug logs enabled, shared key encryption) at ./ise/logs/apigateway/access.log*.gz
  • Cisco warns that successful exploitation grants root-level command execution, so a threat actor may remove evidence on the device itself; Cisco recommends cross-checking network and firewall logs outside the affected device for suspicious activity, including unexpected external uploads or downloads to/from malicious sources.

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.

IDs

  • CVE-2026-76460
  • CWE-648
  • Vendor Advisory: cisco-sa-ISE-ABP-VNSW7Tn5
  • Cisco Bug ID: CSCww39530
  • Tenable Plugin: not yet confirmed (Plugins Pipeline checked 2026-09-17; no matching entry found; pipeline is non-exhaustive)
  • Qualys QID: 317886 (confirmed; pipeline status "In QA", date inserted 2026-09-17)

References

Related Post