www.infosecurity-magazine.com 17 Sept 2026, 11:15 UTC

Attackers Exploit Critical Cisco ISE Flaw for Root Access

Attackers Exploit Critical Cisco ISE Flaw for Root Access
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISCO has warned that attackers are actively exploiting CVE-2026-76460, a maximum-severity vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw, rated CVSS 10.0, results from insufficient control over an API endpoint. Cisco said a crafted request could allow an attacker to bypass the web-based management interface and gain unauthorised access to an affected device. The vulnerability affects the products regardless of their configuration.

Cisco has released software updates and urged customers to install them; no workaround fully addresses the flaw. Until systems can be updated, infrastructure access control lists can limit management and control-plane traffic to help prevent remote exploitation. On 16 September 2026, the US Cybersecurity and Infrastructure Security Agency added CVE-2026-76460 to its Known Exploited Vulnerabilities catalogue, requiring Federal Civilian Executive Branch agencies to prioritise remediation.

Administrators should inspect each node’s access.log for suspicious usernames and review external network and firewall logs for unusual uploads to external IP addresses or downloads from malicious addresses. Cisco warned that successful exploitation could provide root-level command execution, potentially allowing attackers to remove or conceal evidence and indicators of compromise. If malicious activity is suspected, the company recommends re-imaging affected nodes and restoring them from configuration backups where necessary.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline