Cisco issues emergency patches for exploited ISE zero-day
Cisco released emergency updates for a critical ISE authentication bypass (CVE-2026-76460) with a 10/10 CVSS score that is being actively exploited and can grant root access.
Cisco released emergency software updates on Wednesday after a critical authentication bypass in its Identity Services Engine (CVE-2026-76460) was found to be exploited in the wild. The flaw, assigned a 10/10 CVSS score, stems from an API endpoint that fails to enforce proper authentication. Successful attacks can bypass the web-based management interface and gain control of affected appliances.
The vulnerability affects both Cisco ISE and the ISE Passive Identity Connector (ISE-PIC) across all configurations. Cisco provided fixes for supported releases and urged customers to upgrade to ISE or ISE-PIC versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 or 3.1 Patch 12. The company has not published any attribution or identified the groups exploiting the flaw.
Exploitation can allow remote execution of commands with root privileges, which may let an attacker remove or alter indicators of compromise on the device. Cisco’s advisory recommends reviewing the access.log file on each node in distributed deployments for suspicious usernames and checking network and firewall logs outside the device for unexpected uploads or downloads. The advisory adds that when malicious activity is suspected, administrators should re-image affected nodes and restore configurations from backups.
Cisco warned there is no complete workaround that fully mitigates the vulnerability. Infrastructure access control lists that restrict traffic to affected devices can block remote exploitation until patches are applied. The advisory notes that the presence of certain log entries may indicate malicious activity and should be examined on every node in a deployment.
The U.S. Cybersecurity and Infrastructure Security Agency placed CVE-2026-76460 on its Known Exploited Vulnerabilities catalog on Wednesday and instructed federal agencies to apply patches within three days under Binding Operational Directive 26-04. The agency’s action reflects its assessment of active exploitation and the high impact of a successful attack.
Cisco’s Product Security Incident Response Team wrote in the advisory, “The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” Organizations that operate ISE or ISE-PIC should treat affected systems as high priority, check logs for every node in multi-node deployments, and cross-reference external network logs to find evidence an attacker might have tried to remove on the device.
The zero-day adds to a series of recently exploited vulnerabilities affecting enterprise networking and email security products. Organizations using Cisco ISE should apply the supplied updates promptly, implement temporary access restrictions where feasible, and follow forensic guidance if compromise is suspected to remove persistent access and restore systems to a known-good state.







