Active Exploitation Alert: Cisco Identity Services Engine Authentication Bypass (CVE-2026-76460) Added to CISA KEV — Unauthenticated API Bypass to Root on ISE

Active Exploitation Alert: Cisco Identity Services Engine Authentication Bypass (CVE-2026-76460) Added to CISA KEV — Unauthenticated API Bypass to Root on ISE

Executive Summary

CVE-2026-76460 is a critical authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient authentication control on an API endpoint (CWE-648: Incorrect Use of Privileged APIs). An unauthenticated remote attacker can bypass authentication / the web-based management interface via a crafted request to the affected API. Cisco further states successful exploitation may obtain command execution with root privileges. Cisco rates the issue CVSS 3.1 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). There are no workarounds that address the vulnerability; infrastructure ACLs (iACLs) limiting management/control-plane traffic are a temporary mitigation only.

Cisco published advisory cisco-sa-ISE-ABP-VNSW7Tn5 on September 16, 2026 and stated PSIRT is aware of active exploitation. CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog the same day, with a federal remediation due date of September 19, 2026, forensic triage required = Yes, and known ransomware campaign use = Unknown. NVD status is Analyzed (lastModified September 17, 2026). No public threat-actor attribution appears in Cisco or CISA materials reviewed for this advisory.

First fixed releases: 3.1 Patch 12; 3.2 Patch 11; 3.3 Patch 12; 3.4 Patch 7; 3.5 Patch 4. ISE 3.0 has reached End of Software Maintenance and must migrate to a supported fixed release.

Technical Information

Per Cisco, the vulnerability stems from insufficient authentication control on an API endpoint. An unauthenticated remote attacker who can reach the affected API can bypass authentication on the web-based management interface. Cisco warns that successful exploitation may yield command execution with root privileges, and that root access may allow actors to remove or hide on-box evidence—so operators should cross-check external network/firewall logs for unexpected uploads from the device or downloads from malicious endpoints.

The vulnerability was found during resolution of a Cisco TAC support case. Products are affected regardless of device configuration. Exact API endpoint and request shape are not published in the advisory (appropriate given active exploitation).

Primary sources reviewed (Cisco SA, CISA KEV/alert, NVD) do not explicitly map CVE-2026-76460 to MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or APT attribution.

Affected Product Versions

Vendor: Cisco Systems, Inc. Products: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) — regardless of device configuration.

First fixed releases (Cisco Fixed Software table — authoritative for remediation):

  • 3.1 → 3.1 Patch 12
  • 3.2 → 3.2 Patch 11
  • 3.3 → 3.3 Patch 12
  • 3.4 → 3.4 Patch 7
  • 3.5 → 3.5 Patch 4

Cisco ISE 3.0 has reached End of Software Maintenance; migrate to a supported release that includes the fix. Prefer Cisco’s Fixed Software table (and Software Checker where applicable) over partial CNA sample lists or secondary blog paraphrase for inventory decisions. NVD lists extensive CPE matches for identity_services_engine and identity_services_engine_passive_identity_connector across 3.1.0–3.5.0 trains short of the fixed patches.

Workaround and Mitigation

Cisco states there are no workarounds that address the vulnerability. Temporary mitigation: Infrastructure ACLs (iACLs) limiting management/control-plane traffic to the device.

  1. Inventory every Cisco ISE and ISE-PIC node—including nodes operated by MSPs, managed-NAC, SASE, or campus vendors on your behalf—and record exact release + patch versus Cisco’s first-fixed list.
  2. Upgrade to a first-fixed release: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4. Migrate ISE 3.0 to a supported fixed train.
  3. Restrict management exposure with iACLs before/during patch windows where feasible.
  4. Because CISA KEV requires forensic triage (Yes) under BOD 26-04 with due date September 19, 2026 for FCEB, do not close residual risk on “patched” alone—assess for pre-patch compromise.
  5. Review ise-kong/access.log (support bundle path ./ise/logs/apigateway/access.log) on every node for suspicious usernames (Cisco provides a non-exhaustive example filter referencing dummyuser); cross-check external firewall/NetFlow/proxy telemetry for unexpected ISE-originated uploads/downloads.
  6. If compromise is suspected: follow Cisco’s re-image and config-restore guidance; re-validate authorization policies, admin accounts, and certificates that downstream customer segments trust.

Indicators of Compromise

Cisco, CISA, and NVD do not publish traditional IoC packages (malware hashes, C2 IPs, or domains) for CVE-2026-76460 in the sources reviewed.

Honest empty for traditional public IoCs: none disclosed as of this pack date (2026-09-18).

Cisco does publish hunting guidance: review access.log / ise-kong for suspicious usernames (non-exhaustive example filter); check every node; cross-check external network/firewall logs because root may allow on-box IoC removal. Treat these as vendor-sourced investigation leads, not an invented IoC list. Do not invent ATT&CK IDs or additional indicators.

References

Third-Party Risk Bridge: Shared ISE as Identity/NAC Control Plane

Cisco ISE is the identity/NAC control plane for enterprises and MSP-managed networks. An unauthenticated API authentication bypass on a shared or vendor-managed ISE can forge session trust, alter authorization policy, and pivot across every customer network segment that trusts that ISE—not merely a local admin UI bug. Cisco confirmed active exploitation; CISA’s KEV listing requires forensic triage (Yes) with a September 19, 2026 federal due date. Ask every MSP, managed-NAC, SASE, or campus vendor whether they operate ISE/ISE-PIC for you, which exact release+patch each node runs versus Cisco’s first-fixed list, whether iACLs restricted management exposure, and whether access.log hunting plus external egress telemetry were reviewed—because root may wipe on-box evidence.

Book a demo to see how Rescana tracks identity/NAC and MSP vendors for KEV-class ISE control-plane risk, version attestation, and forensic-triage evidence.

Forward this advisory to your TPRM owner if an MSP or managed-NAC provider issues RADIUS/TACACS+/pxGrid/SAML or posture decisions into your estate—they own the patch-per-node, log-hunting, and session-trust attestation asks above.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.

Active Exploitation of JFrog Artifactory Vulnerabilities Enables Backdoor Deployment and Supply Chain Risk
Sep 14, 2026
Active Exploitation of JFrog Artifactory Vulnerabilities Enables Backdoor Deployment and Supply Chain Risk
Active Exploitation Alert: Citrix NetScaler ADC/Gateway Authentication Bypass (CVE-2026-19490) Added to CISA KEV — Patch and Forensic Triage Guidance
Sep 14, 2026
Active Exploitation Alert: Citrix NetScaler ADC/Gateway Authentication Bypass (CVE-2026-19490) Added to CISA KEV — Patch and Forensic Triage Guidance