CISCO has released urgent patches for a critical authentication-bypass vulnerability in Identity Services Engine (ISE) that its security response team says is being actively exploited as a zero-day. Tracked as CVE-2026-76460 and rated 10/10 for severity, the flaw affects an API endpoint that does not enforce sufficient authentication. Attackers can send crafted requests to bypass the web-based management interface and access the appliance. Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected regardless of configuration, and Cisco has not identified who is behind the attacks.
Customers should upgrade to ISE or ISE-PIC version 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 or 3.1 Patch 12. No workaround is available, although Cisco says infrastructure access control lists can restrict traffic and prevent remote exploitation. Successful exploitation may allow attackers to execute commands with root privileges, including hiding or deleting indicators of compromise.
Administrators should review `access.log` on every node for suspicious usernames, check network and firewall logs for unexpected uploads or downloads, and, where compromise is suspected, re-image affected nodes and restore them from configuration backups. The US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalogue, requiring US federal agencies to address it within three days.