Skip to main content
QUIETLYTIC
Vulnerability

Cisco Identity Services Engine Authentication Bypass (CVE-2026-76460)

CVE-2026-76460 is a CVSS 10.0 unauthenticated API authentication bypass in Cisco ISE and ISE-PIC, CISA KEV-listed Sept. 16, 2026, with no vendor workaround.

CVE-2026-76460
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
High
Affected Products
Cisco Identity Services Engine, Cisco ISE Passive Identity Connector

CVE-2026-76460 is an authentication bypass in a Cisco Identity Services Engine API, scored CVSS 3.1 base 10.0, and it went from CVE publication to CISA Known Exploited Vulnerabilities listing on the same day — September 16, 2026. Cisco’s own advisory states there are no workarounds. The only remediation is a patched release.

That same-day KEV listing is the signal worth reading first. CISA adds a CVE to the catalog on evidence of real-world exploitation. Our assessment: a listing dated to the disclosure day is consistent with exploitation that predates the advisory — Cisco found the flaw while resolving a customer support case, and its PSIRT states it is aware of active exploitation.

What the flaw is

Per NVD and the CVE Record, the root cause is insufficient authentication control on an API endpoint in Cisco ISE. A remote attacker with no credentials can reach functionality that the web-based management interface is supposed to gate, obtaining unauthorized access to the device. NVD, CISA KEV, VulnCheck KEV and cve.org all classify it under CWE-648, incorrect use of privileged APIs — four sources in agreement on the weakness class.

NVD scores it CVSS 3.1 base 10.0 with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Two components of that vector carry the weight. PR:N means no prior foothold, no credential, no phished session — the precondition is network reachability to the API. S:C means the impact does not stay inside the vulnerable component; a scope change is what lifts a full-impact network flaw from 9.8 to a clean 10.0.

Cisco’s advisory adds a detail our ingested data does not carry: it states that a successful attacker can end up running commands as root on the appliance. That is the practical reading of the scope change.

Which products, and a scoping trap

The CISA KEV and VulnCheck KEV entries both record the affected product as “Identity Services Engine.” The CVE Record is more specific and lists two: Cisco Identity Services Engine Software and Cisco ISE Passive Identity Connector. Cisco’s advisory confirms the wider reading — both products are affected regardless of device configuration.

An operator scoping exposure from the KEV product string alone would miss ISE-PIC deployments. Where sources differ in granularity like this, the narrower one is not the safer one.

Cisco’s advisory lists the first fixed release per train: ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Release 3.0 has reached end of software maintenance and receives no fix.

What the evidence actually supports

Claim Value Sources agreeing Confidence
Exploitation status KEV-listed, active exploitation CISA KEV, VulnCheck KEV, Cisco PSIRT High
KEV date added 2026-09-16 CISA KEV, VulnCheck KEV High
Weakness class CWE-648 NVD, CISA KEV, VulnCheck KEV, cve.org High
Vendor Cisco NVD, CISA KEV, VulnCheck KEV, cve.org High
Affected products ISE and ISE-PIC cve.org, Cisco advisory (KEV: ISE only) High
CVSS score / vector 10.0, AV:N/AC:L/PR:N/UI:N/S:C/… NVD (Cisco’s advisory states 10.0 also) High
EPSS 0.00784 (54.5th percentile) FIRST EPSS Medium

The exploitation claim here is as strong as this publication’s evidence model allows: two KEV catalogs agree, and the vendor’s own PSIRT states it independently. Nothing in our data contradicts it.

Why this matters

The EPSS number is the interesting tension. At 0.00784 — under a 1% modelled probability of exploitation in the next 30 days, 54th percentile — EPSS reads this as unremarkable. CISA and Cisco both say it is being exploited now.

That is not an EPSS failure so much as a description of what EPSS measures. The model is trained on observable signal — internet-wide scanning telemetry, public disclosure activity, and the characteristics of vulnerabilities that have historically attracted opportunistic attention. A flaw found while Cisco TAC was working a customer support case, and exploited against a product that sits inside enterprise networks rather than on the public internet, generates very little of that signal. Our assessment: where KEV and EPSS disagree in this direction, KEV wins the prioritisation argument outright. EPSS is a forecast; a KEV listing is an observation.

What ISE is compounds it. Identity Services Engine is a network access control and policy server — it decides which endpoints are admitted to the network and under what authorisation, and it is routinely integrated with directory services. Root on that host is not one compromised appliance; it is the component that arbitrates access for everything downstream.

Cisco’s advisory also notes that because exploitation can yield root, indicators of compromise may have been removed by the attacker, and recommends re-imaging affected nodes and restoring from a configuration backup where malicious activity is suspected. Detection guidance is to review the API gateway access log on every node in a distributed deployment for usernames that should not be there, and to cross-check network and firewall logs outside the appliance for unexpected transfers to or from external addresses. Patching a device that may already be compromised is not the same job as remediating one that is not.

Where an upgrade cannot happen immediately, Cisco offers one temporary mitigation rather than a workaround: infrastructure access control lists restricting management and control plane traffic to the appliance. That reduces who can reach the endpoint. It does not fix the endpoint.

Cisco’s September exposure, in context

This is the third Cisco product this publication has covered from CISA’s September 2026 KEV additions, and the pattern across them is consistent. CVE-2026-20079, KEV-listed September 9, was also a CVSS 10.0 authentication bypass — in Firewall Management Center, another management-plane product. CVE-2026-76461, KEV-listed September 14 and carrying a CVE ID adjacent to this one, was a 9.8 SQL injection in Secure Email Gateway.

Three critical flaws, three different products, one shared property: each is a security-function appliance with a defect reachable without credentials. Where the compromised device is itself part of the security control set — policy enforcement, perimeter management, mail inspection — the loss is not one host among many. For organisations running more than one Cisco security appliance, treating these as three separate patch tickets underestimates the correlated exposure.

What we don’t have

  • No affected-version data in our ingested sources. The fixed-release list above comes from Cisco’s advisory, read directly; NVD, CISA KEV and VulnCheck KEV carry no version ranges for this CVE.
  • No exploitation detail. Neither KEV catalog nor Cisco’s advisory names an actor, a campaign, or an observed volume. We have confirmation that exploitation is happening and nothing about who or how many — and we will not speculate to fill that in.
  • Advisory titles differ across sources. CISA KEV and VulnCheck KEV title this “Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability”; cve.org and Cisco title it “Authentication Bypass Vulnerability.” Same defect, different labels — worth knowing when searching catalogs.

Frequently Asked Questions

What is CVE-2026-76460? A CVSS 10.0 authentication bypass (CWE-648) in an API of Cisco Identity Services Engine and ISE Passive Identity Connector. Insufficient authentication control on an API endpoint lets an unauthenticated remote attacker gain unauthorized access to the device, bypassing the web-based management interface.

Is CVE-2026-76460 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 16, 2026, VulnCheck’s KEV catalog lists it the same day, and Cisco’s PSIRT states in its advisory that it is aware of active exploitation. This is high-confidence exploitation evidence by any reasonable standard.

Is there a workaround for CVE-2026-76460? No. Cisco states there are no workarounds. It offers one temporary mitigation — infrastructure access control lists limiting management and control plane traffic reaching the appliance — but the remediation is an upgrade to a fixed release.

Which Cisco ISE versions fix CVE-2026-76460? Per Cisco’s advisory: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. ISE 3.0 has reached end of software maintenance, so affected 3.0 deployments must migrate to a supported release.

Does BOD 26-04 apply to CVE-2026-76460? Yes. The CVE is on CISA’s KEV catalog, which is what triggers Binding Operational Directive 26-04 remediation obligations for federal civilian agencies.


Data sourced from the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities Catalog, VulnCheck KEV, FIRST EPSS and cve.org, aggregated September 19, 2026. Vendor advisory: cisco-sa-ISE-ABP-VNSW7Tn5. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools