HomeSecurityCisco ISE: Critical vulnerability under active exploitation

Cisco ISE: Critical vulnerability actively exploited

The cybersecurity community is on edge after the disclosure of a critical vulnerability in Cisco Identity Services Engine (ISE), which has already gone from theoretical threat to actual exploitation. Cisco has released urgent security updates for the issue, as the Product Security Incident Response Team (PSIRT) confirmed that attackers are exploiting the vulnerability in attacks.

Cisco ISE: Critical vulnerability

The vulnerability is listed as CVE-2026-76460 and has a CVSS score of 10.0, the maximum severity rating. The issue affects an API in Cisco ISE and the ISE Passive Identity Connector (ISE-PIC) and could allow a remote, unauthenticated attacker to bypass the authentication mechanism.

Why Cisco ISE is a critical target

Cisco ISE is used by organizations to centrally manage network access policies. Through the platform, administrators can control users, endpoints, and devices, determining who has access to specific resources.

Its role becomes even more important in environments that implement Zero Trust, where the identity and state of a device are key elements in the access decision. Therefore, a weakness in the authentication mechanism itself can pose a serious risk to the infrastructure behind it.

See also: Issabel Framework: CVE-2026-89026 exposes PBX via shared JWT key

Bypass API authentication

According to Cisco, CVE-2026-76460 is caused by insufficient authentication in an API endpoint. An attacker could send a specially crafted request to the vulnerable endpoint, without requiring prior authentication.

If successfully exploited, an attacker could gain unauthorized access to the affected deviceby bypassing the web-based management interface. The fact that the attack can be carried out remotely and without valid credentials largely explains the severity of the vulnerability.

There is no workaround

Adding to the pressure on administrators is the fact that there is no workaround available that permanently addresses the issue. Cisco recommends immediately upgrading to a software version that includes the fix.

The patched versions include 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, depending on the version of ISE being used. For older versions that are no longer supported, Cisco recommends migrating to a supported version.

Cisco ISE: Critical vulnerability actively exploited

What administrators should check

Installing the patch is the first step, but in case a system is already exposed, security teams should also examine available logs for signs of a breach.

Pay special attention to access logs, as well as firewall and network logs. Suspicious connections, unusual data uploads or downloads, and communications with unknown external IP addresses can be indications that an attacker has gained access.

See also: Critical vulnerability in WSO2 API Manager actively exploited

Cisco also notes that if malicious activity is suspected, organizations should consider re-imaging nodes and restoring them from trusted backups. This need is related to the risk that attackers have gained the ability to execute commands with elevated privileges and have attempted to cover their tracks.

New set of problems in Cisco ISE

CVE-2026-76460 is not the only issue currently facing the platform. Cisco released a broader set of security hardening updates for ISE and ISE-PIC on September 16, addressing multiple vulnerabilities identified during internal security audits.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Issues related to remote code execution, command injection, and other categories of vulnerabilities were also published during the same period . For example, Cisco has documented command injection vulnerabilities with CVSS 9.1, which can, under certain conditions, lead to the execution of commands as root.

The previous one of 2025

The current case takes on even greater significance given the history of Cisco ISE. In 2025, another serious zero-day vulnerability was discovered in the platform, which was used in attacks for remote code execution and installation of a malicious web shell.

The fact that ISE has been a target of attacks in the past highlights why these infrastructures are considered particularly attractive to attackers: compromising a platform that manages identities and access policies can be a starting point for further penetration into a corporate network.

See also: WebSocket vulnerability allows module injection

Cisco ISE: Critical vulnerability actively exploited

CISA KEV membership increases pressure

The importance of CVE-2026-76460 is also reflected in its inclusion on the Known Exploited Vulnerabilities (KEV) . The listing of such vulnerabilities is a strong indication that organizations should not treat the issue as a simple preventive update, but as a risk that requires immediate assessment and remediation.

For enterprises using Cisco ISE, the key message is clear: check the version, install the available fix immediately, and simultaneously check the logs for a possible previous breach. In a platform so close to the core of access management, delaying the application of a patch can significantly increase the window of opportunity for an already active attacker.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS