Cisco has released a fix for a maximum-severity flaw in its Identity Services Engine (ISE) platform after confirming the bug was already being exploited by attackers. The vulnerability, tracked as CVE-2026-76460, carries a perfect CVSS score of 10.0 and was patched by Cisco on September 16, 2026.
The flaw sits in an API within Cisco Identity Services Engine and stems from inadequate authentication checks on an API endpoint. Because of this weakness, an unauthenticated attacker could send a specially crafted request to that endpoint and slip past ISE’s web-based management interface entirely, gaining unauthorized access to the device without needing valid credentials.
Given that Cisco confirmed active exploitation of CVE-2026-76460, the Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog, a designation reserved for bugs already being weaponized in real-world attacks.
Cisco ISE has long served as one of the most widely deployed network access control tools in enterprise environments, helping organizations manage security policies centrally, confirm the identities of users and devices, and govern who and what can reach different parts of a network. That central role is precisely what makes a bypass of its authentication so dangerous, according to security researchers.
John Strand, owner of Black Hills Information Security, echoed the urgency, recommending that affected organizations patch immediately and disconnect ISE instances from direct internet exposure. Strand also warned that the bug could plausibly be leveraged in a ransomware attack.
Even so, he noted that relatively few ISE deployments appear to be directly exposed to the open internet, which limits the number of organizations at risk from an opportunistic, internet-facing attack. His larger concern is what happens after attackers are already inside a network: “I’d be more concerned about it as a post-exploitation lateral movement opportunity.
An attacker gets into the environment through something else, discovers a vulnerable ISE internally, and uses that to expand access or compound the damage.”
Cisco’s advisory notes that successful exploitation can hand attackers root-level command execution, meaning they could potentially erase or mask evidence of their intrusion. The company is advising administrators to cross-reference network and firewall logs from outside the affected device to spot unusual activity, including unexpected data transfers to external addresses.
Suspicious usernames in the access logs are cited as one possible indicator of compromise, and Cisco recommends checking every node in a distributed deployment.
The vulnerability affects Cisco ISE and ISE Passive Identity Connector regardless of how a device is configured. No workarounds exist, though Cisco suggests using infrastructure access control lists to restrict management traffic as a temporary mitigation.
Fixed releases are available for versions 3.1 through 3.5, including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Version 3.0 has already reached the end of software maintenance, so organizations still running it are advised to migrate to a supported release.
The issue was discovered during a Cisco Technical Assistance Center support case, and the advisory was published in final form on September 16, 2026.