Cisco ISE Authentication Bypass Vulnerability Hits Root

A Cisco ISE authentication bypass vulnerability (CVSS 10.0) lets attackers reach root with no credentials. Active exploitation confirmed. Patch now.

A Cisco ISE authentication bypass vulnerability tracked as CVE-2026-76460 carries a perfect CVSS score of 10.0 and is already under active exploitation. An unauthenticated attacker can bypass Cisco Identity Services Engine’s web-based management interface entirely and, per Cisco’s own advisory, reach command execution as root. That is the one system in your network built to enforce who gets access to what.

What Happened

Cisco disclosed CVE-2026-76460 on September 16-17, 2026, affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. The root cause is insufficient authentication enforcement on an API endpoint: a specially crafted, unauthenticated request bypasses the management interface’s login entirely. Cisco states that successful exploitation may ultimately grant command execution with root privileges on the underlying appliance.

Cisco confirmed active exploitation at disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16, with a federal remediation deadline of September 19, already elapsed by the time most organizations outside the federal civilian sector will read this. Fixed releases are available: ISE 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, and 3.1 Patch 12. Cisco states there is no workaround that fully addresses the vulnerability short of patching, though restricting management-interface access via infrastructure access control lists (iACLs) reduces remote exposure in the meantime.

This is the second Cisco zero-day disclosed within a single week. DIESEC covered a Secure Email Gateway flaw, CVE-2026-76461, on September 17. Two different Cisco product lines, two different attack surfaces, inside the same seven-day window.

Why It Matters

ISE is not just another appliance: it is the system that decides which devices and users get network access, and under what policy. Root access on an ISE box means an attacker can rewrite that policy directly, extract every credential and certificate ISE has stored, delete audit logs covering its own intrusion, and pivot laterally into any network segment ISE was trusted to gate. For DACH Mittelstand organizations running Cisco ISE as their network access control backbone (common in manufacturing, finance, and regulated industries with segmented OT/IT environments), this converts a single unpatched appliance into a master key for the rest of the network.

What You Should Do Now

  1. Patch immediately to ISE 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12, whichever matches your current branch; there is no version this flaw does not affect.
  2. Verify exposure by checking whether your ISE management interface is reachable from outside a restricted administrative network; if it is internet-facing at all, treat it as compromised until confirmed otherwise.
  3. Until patched, restrict access to the management interface using infrastructure ACLs limited to known administrative source IPs; this is Cisco’s own stated interim mitigation, not a substitute for the patch.
  4. After patching, review ISE audit logs and any downstream systems that trust ISE-issued policy decisions for signs of unauthorized policy changes, new admin accounts, or credential extraction predating the patch.

DIESEC Perspective

This is the second Cisco zero-day DIESEC has tracked in the same week, following the Secure Email Gateway flaw covered here on September 17. Two unrelated product lines, two unrelated attack surfaces, disclosed days apart; a pattern worth watching rather than a coincidence to shrug off, particularly for organizations running multiple Cisco products as their network security backbone.

Not sure whether your network access control policy has been reviewed since this disclosure? Contact DIESEC for a rapid identity-configuration review.

Sources: BleepingComputer | SecurityWeek
Published: 2026-09-22 | Category: Vulnerabilities & Patches | ~4 min read