Summary
- CVE-2026-76460 allows an unauthenticated remote attacker to bypass the Cisco ISE web management interface.
- Cisco confirms active exploitation and provides fixed releases across supported ISE branches.
- Cisco warns that successful attackers may subsequently obtain root command execution and conceal local evidence.
Cisco has patched a maximum-severity authentication bypass in Identity Services Engine after confirming that attackers are exploiting the flaw in live environments.
CVE-2026-76460 carries a CVSS score of 10.0 and affects Cisco ISE and ISE Passive Identity Connector regardless of device configuration. The vulnerability is caused by insufficient authentication control on an API endpoint.
A remote attacker does not need credentials to exploit the flaw. Cisco says a crafted request can bypass the web-based management interface and give the attacker unauthorised access to the affected device.
The company separately warns that after successful exploitation, threat actors may obtain command execution with root privileges. That distinction is important: the documented vulnerability initially bypasses management authentication, while the highest level of control can follow once an attacker has gained access.
Cisco discovered the issue while resolving a Technical Assistance Center support case and says its Product Security Incident Response Team is aware of active exploitation. It has not publicly attributed the activity to a named group or disclosed the number of affected environments.
Fixed releases include ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco lists no workaround that fully addresses the vulnerability, although it recommends infrastructure access-control lists as a temporary mitigation to restrict management and control-plane traffic.
NHS England’s National Cyber Security Operations Centre issued a UK alert on 17 September and assessed further exploitation as highly likely.
ISE occupies a sensitive position in enterprise architecture. It can centralise network access control, authentication policy, device profiling, and segmentation decisions, determining which users and systems can gain access to network resources.
Compromise of that control plane is consequently different from compromise of an ordinary endpoint. An attacker who gains administrative control over the system may gain visibility into configuration and policy and may be able to interfere with mechanisms intended to restrict access elsewhere in the environment.
Cisco’s incident guidance also reflects the evidential problem created by root access. The company warns that attackers at that privilege level may remove or conceal indicators of compromise stored locally.
Administrators are therefore advised to cross-check network and firewall logs held outside the affected ISE node for suspicious uploads, downloads, or communication with external infrastructure rather than relying only on the appliance’s own records.
The advisory formed part of a larger September security release for ISE following an internal review. Cisco disclosed several other vulnerability classes at the same time, but it says it is not aware of malicious use of those separate issues.
CVE-2026-76460 stands apart because active exploitation is confirmed, no authentication is required to reach the vulnerable API, and the affected system participates directly in enterprise access decisions.
Identity and network-control infrastructure has become an increasingly valuable attack surface precisely because it governs access to other systems. A compromise at that layer can weaken the boundary intended to contain later movement, while privileged access to the appliance can also make incident reconstruction harder if locally stored evidence is no longer trustworthy.





