CISCO has disclosed CVE-2026-76460, a maximum-severity authentication-bypass vulnerability in an API endpoint used by its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Rated 10 out of 10 on the CVSS scale, the flaw results from insufficient authentication controls. Cisco says an attacker can send a specially crafted request to bypass the web-based management interface and gain unauthorised access to an affected device.
Successful exploitation requires no authentication or user interaction and can provide root privileges and command execution. The flaw was disclosed and patched on 16 September 2026, and the US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalogue the same day, confirming exploitation in the wild. However, the attacker or attackers and the scale of activity remain unknown.
The vulnerability affects ISE and ISE-PIC regardless of device configuration. Cisco has issued fixes for versions 3.1 through 3.5; version 3.0 is unsupported and customers are advised to upgrade. As a temporary measure, infrastructure access control lists can restrict management and control-plane traffic to prevent remote exploitation, but Cisco stresses that this is not a replacement for installing the relevant update.
Because exploitation can grant root access and allow attackers to remove or hide evidence, Cisco recommends checking network and firewall logs outside the affected device for suspicious activity, including unexpected uploads to external IP addresses or downloads from malicious addresses. Security experts warn that compromising ISE could also undermine network authentication and access-control decisions made by connected systems.