securityonline.info 16 Sept 2026, 17:26 UTC

Cisco Warns Attackers Are Exploiting Critical ISE Flaw with Root Access

Cisco Warns Attackers Are Exploiting Critical ISE Flaw with Root Access
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISCO warned on 16 September 2026 that attackers are actively exploiting a critical vulnerability in its Identity Services Engine (ISE) and ISE-PIC products. Tracked as CVE-2026-76460, the flaw has a CVSS score of 10.0 and stems from insufficient authentication controls on an API endpoint. Unauthenticated remote attackers can send specially crafted network requests to bypass the web management interface and execute commands with root privileges.

Cisco said its Product Security Incident Response Team (PSIRT) was aware of exploitation in the wild; the company reportedly discovered the issue while handling a Technical Assistance Center support case.

Cisco ISE releases 3.1 through 3.5 are affected across all device configurations. Because ISE enforces identity and network-access policies, a compromise could allow attackers to alter access rules and move into internal networks. The article also says attackers may erase logs and advises checking for suspicious entries involving the `dummyuser` account. Cisco has issued fixes in ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.

There is no temporary workaround, so administrators should apply the relevant update immediately. Where patching cannot be completed at once, infrastructure access-control lists can be used to block untrusted traffic.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline