www.securityweek.com 17 Sept 2026, 06:19 UTC

Cisco ISE Zero-Day Lets Attackers Gain Root Access Without Login

Cisco ISE Zero-Day Lets Attackers Gain Root Access Without Login
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISCO has released urgent patches for a critical authentication-bypass vulnerability in Identity Services Engine (ISE) that its security response team says is being actively exploited as a zero-day. Tracked as CVE-2026-76460 and rated 10/10 for severity, the flaw affects an API endpoint that does not enforce sufficient authentication. Attackers can send crafted requests to bypass the web-based management interface and access the appliance. Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected regardless of configuration, and Cisco has not identified who is behind the attacks.

Customers should upgrade to ISE or ISE-PIC version 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 or 3.1 Patch 12. No workaround is available, although Cisco says infrastructure access control lists can restrict traffic and prevent remote exploitation. Successful exploitation may allow attackers to execute commands with root privileges, including hiding or deleting indicators of compromise.

Administrators should review `access.log` on every node for suspicious usernames, check network and firewall logs for unexpected uploads or downloads, and, where compromise is suspected, re-image affected nodes and restore them from configuration backups. The US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalogue, requiring US federal agencies to address it within three days.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline