Cisco Fixes Critical CVE-2026-76460 Flaw in ISE as Attacks Are Underway
Cisco has released fixes for the critical CVE-2026-76460 flaw in ISE and ISE-PIC systems. Cisco reports active exploitation, while CISA added it to the KEV catalog on September 16, 2026.

CVE-2026-76460 is a critical authentication bypass vulnerability in the APIs of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. Cisco has released fixes and reports active exploitation. The U.S. agency CISA added the flaw to the Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026.
The flaw has a maximum CVSS score of 10.0. An unauthenticated remote attacker can send a crafted request to the vulnerable API and gain unauthorized access by bypassing the web administration interface. According to Cisco, no user interaction is required.
CVE-2026-76460 Affects Both ISE and ISE-PIC
The vulnerability affects Cisco ISE and Cisco ISE-PIC regardless of device configuration. These platforms are used to manage network identity, so Cisco recommends prioritizing deployment of the relevant fix, especially if the administration interface is exposed or inadequately segmented.
Cisco PSIRT states that it has information about active exploitation of the flaw. CISA added it to the KEV catalog on September 16, 2026. CISA recommends that organizations follow the manufacturer’s instructions and patch-prioritization rules.
However, details about the scope of the activity are not publicly known. Cisco and CISA have not disclosed the attackers’ identities, the number of affected organizations, specific campaigns, or the number of incidents.
Available Fixes and Temporary Access Restrictions
Cisco has made fixes available for these releases:
- ISE/ISE-PIC 3.1 Patch 12,
- ISE/ISE-PIC 3.2 Patch 11,
- ISE/ISE-PIC 3.3 Patch 12,
- ISE/ISE-PIC 3.4 Patch 7,
- ISE/ISE-PIC 3.5 Patch 4.
No workaround is available for CVE-2026-76460. As a temporary mitigation, Cisco recommends using an iACL, or infrastructure access control lists, to restrict access to the control plane to only essential communication. However, this is not a replacement for the fix.
Organizations should verify the ISE and ISE-PIC versions in use, deploy the corresponding patch, and review device logs and external network records for possible unusual requests directed at the administration API.
Potential Scope of Access After Exploitation
Cisco warns that after successful exploitation, an attacker could potentially gain the ability to execute commands with root privileges. However, publicly available information does not confirm that such command execution occurred in every known exploitation case.
Further information may come from updated Cisco security advisories, including any indicators of compromise. It will also be important to monitor for the publication of technical details, exploits, or confirmed incidents from organizations and security agencies.
Sources
- Cisco Security Advisory – Confirms the nature of the flaw, CVSS 10.0, affected products and versions, available fixes, the absence of a workaround, iACL mitigation, and active exploitation according to Cisco PSIRT.
- CISA Known Exploited Vulnerabilities Catalog – Confirms that CVE-2026-76460 was added to the CISA KEV catalog and the requirement to follow the manufacturer’s instructions and federal patch-prioritization rules.
Verified and updated: September 17, 2026 06:21



