Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway appliance.
The Cisco ISE flaw, tracked as CVE-2026-76460, has the maximum severity score of 10.0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device. The vulnerability is in an API endpoint used for management and can be exploited by sending crafted requests that bypass the normal web-based management interface completely.
The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, depending on which major software release is being used.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, indicating that exploitation in the wild has been confirmed.
Mitigation
Users of Cisco ISE and ISE-PIC are advised to check the access.log on their devices and search for suspicious usernames, which could be an indicator of successful compromise. However, because attackers gain root access through this vulnerability, they could delete the logs to hide their tracks, in which case network and firewall logs upstream of the devices should also be checked for suspicious activity such as file uploads and downloads initiated from the devices with unauthorized IP addresses.
“If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed,” the company said.
Cisco also advises administrators use infrastructure access control lists (iACLs) to limit who can send management and control traffic to the affected devices.
More critical flaws patched in Cisco ISE
This is not the only vulnerability fixed in Cisco ISE this week. The company did a comprehensive review of the Cisco ISE and ISE-PIC platforms, uncovering and fixing a total of 21 critical vulnerabilities, including remote code execution ones and other API flaws that fall in the same class as CVE-2026-76460. The releases also address three high-severity flaws and 18 medium-severity ones.
Separately the company also patched critical- and medium-severity flaws in Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software. Older vulnerabilities in these products have been exploited by different threat actors this year, particularly CVE-2026-20079 and CVE-2026-20131 affecting the FMC software that were originally patched in March.
No Responses