CVE / NVD / KEV
Vendor advisories
Cisco has disclosed active exploitation of CVE-2026-76460, a critical authentication-bypass vulnerability affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw carries a CVSS v3.1 base score of 10.0 and can allow an unauthenticated remote attacker to gain unauthorized access to an affected appliance. Cisco published its advisory on September 16, 2026.
Successful exploitation can have consequences beyond unauthorized access to the web-based management interface. Cisco states that attackers may obtain command execution with root privileges, potentially allowing them to remove or conceal evidence of compromise. This makes compromise assessment important for vulnerable systems that were attacker-reachable before remediation.
CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) Catalog on September 16, according to the Canadian Centre for Cyber Security, which links to CISA's KEV entry.
What CVE-2026-76460 allows an attacker to do
CVE-2026-76460 is associated with CWE-648, Incorrect Use of Privileged APIs, and affects an API within Cisco ISE. According to Cisco's advisory, insufficient authentication controls on an API endpoint allow an unauthenticated remote attacker to send a crafted request to an affected system. Successful exploitation bypasses the web-based management interface and provides unauthorized access to the device.
Cisco assigned the vulnerability the CVSS v3.1 vector `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H`. This reflects network-based exploitation, low attack complexity, no required privileges or user interaction, and high confidentiality, integrity, and availability impacts.
Cisco's indicator-of-compromise guidance further clarifies the potential post-exploitation impact: a successful attacker may obtain command execution with root privileges. At that level of access, an attacker may also be able to interfere with evidence stored locally on the appliance.
Cisco discovered CVE-2026-76460 while resolving a Technical Assistance Center (TAC) support case. Cisco PSIRT confirms active exploitation but does not identify a threat actor or attribute the activity to a named campaign.
As of September 18, 2026, the authoritative evidence reviewed here does not establish a public proof-of-concept exploit, the scale of exploitation, a specific victim profile, a named threat actor, or a connection to ransomware. Those points should not be inferred from Cisco's confirmation of active exploitation.
Affected ISE and ISE-PIC releases
Cisco states that CVE-2026-76460 affects both ISE and ISE-PIC regardless of device configuration. Fixed software is available across the 3.1 through 3.5 release branches.
Organizations should upgrade to at least:
- ISE/ISE-PIC 3.1: Patch 12
- ISE/ISE-PIC 3.2: Patch 11
- ISE/ISE-PIC 3.3: Patch 12
- ISE/ISE-PIC 3.4: Patch 7
- ISE/ISE-PIC 3.5: Patch 4
Cisco states that ISE Software Release 3.0 has reached End of Software Maintenance and advises customers using that release to migrate to a supported release containing the fix. Administrators should verify every deployed node and its exact patch level rather than limiting inventory checks to selected ISE release branches.
Active exploitation makes compromise assessment a priority
Cisco PSIRT explicitly reports active exploitation of CVE-2026-76460. The Canadian Centre for Cyber Security also noted Cisco's confirmation of exploitation in a September 17 alert and reported that CISA added the vulnerability to KEV on September 16.
The confirmed exploitation means remediation should not be limited to patching. Vulnerable systems that were reachable by potential attackers before remediation warrant investigation for attempted or successful exploitation.
ISE can occupy a sensitive position in enterprise identity and network-access enforcement architecture. A compromise may therefore affect not only the integrity of the appliance but also confidence in a system used to make security and access-control decisions.
Investigate for evidence of exploitation
Cisco provides specific forensic guidance for affected systems. Administrators should review `ise-kong/access.log` for suspicious usernames. In distributed ISE deployments, Cisco says logs on every node should be examined.
Additional API gateway access logs can be obtained from a support bundle. Cisco identifies the historical log location as:
./ise/logs/apigateway/access.log.<date>.gzLocal appliance logs should not be treated as the sole source of evidence. Cisco warns that successful exploitation may provide root-level command execution, potentially allowing an attacker to hide or remove indicators of compromise. Cisco therefore strongly recommends cross-checking network and firewall logs retained outside the affected appliance.
Defenders should investigate suspicious activity including unexpected uploads initiated by affected appliances to external IP addresses and downloads from malicious IP addresses. The Canadian Cyber Centre additionally recommends reviewing firewall, network, and authentication logs for anomalous activity associated with affected systems.
If malicious activity is suspected, Cisco strongly recommends re-imaging affected nodes and restoring from configuration backup if necessary. Canada's Cyber Centre similarly recommends re-imaging affected nodes and restoring from known-good backups when compromise is suspected.
No workaround is available
Cisco states that there is no workaround that addresses CVE-2026-76460. Installing fixed software is required to remediate the underlying vulnerability.
Cisco does provide an exposure-reduction measure. Infrastructure access control lists, or iACLs, can restrict management and control-plane traffic destined for affected devices to required sources. Cisco explicitly describes this as a mitigation rather than a workaround. Canada's Cyber Centre also recommends restricting management-interface access using ACLs, network segmentation, and trusted administration networks where feasible.
These measures should not substitute for updating. Defenders should identify every ISE and ISE-PIC node, establish its exact patch level, determine how affected services were reachable, install the applicable fixed release, and investigate relevant pre-patch activity using both appliance logs and independently retained telemetry.
Other ISE vulnerabilities were disclosed at the same time
CVE-2026-76460 was not Cisco's only ISE security disclosure on September 16. Cisco published a broader set of ISE advisories covering critical issues involving authentication and access-control weaknesses, remote code execution, command injection, and other vulnerability classes, as reflected in Cisco's security advisory publications.
The Canadian Cyber Centre specifically highlighted CVE-2026-20192, CVE-2026-76423, and CVE-2026-76460. Its guidance gives CVE-2026-76460 particular remediation priority because of confirmed in-the-wild exploitation.
Administrators should therefore review Cisco's broader September 2026 ISE security publications rather than assume that remediating CVE-2026-76460 addresses every vulnerability disclosed for their deployed ISE release.
Defensive priorities for ISE operators
Organizations running Cisco ISE or ISE-PIC should treat CVE-2026-76460 as an urgent vulnerability-management issue and, where systems were vulnerable and attacker-reachable, a potential incident-response trigger.
Defenders should:
- Inventory every ISE and ISE-PIC node and establish its exact release and patch level.
- Upgrade each affected node to Cisco's applicable fixed release.
- Restrict access to management services using iACLs, segmentation, and trusted administrative networks where feasible.
- Preserve and examine relevant ISE API logs, including logs from every node in distributed deployments.
- Correlate appliance findings with externally retained firewall, network, authentication, and other security telemetry.
- Investigate suspicious uploads, downloads, and other anomalous communications involving affected appliances.
- Re-image affected nodes and restore from appropriate backups when malicious activity is suspected, in accordance with Cisco's guidance.
Cisco has confirmed active exploitation but has not publicly attributed it to a threat actor or documented the scale or victimology of the exploitation in its advisory. Those remain important unknowns. Organizations should continue monitoring Cisco PSIRT, CISA, and relevant national cyber authorities for additional exploitation details or indicators.
Because successful exploitation may provide root-level command execution and allow evidence to be removed or concealed, patching alone cannot establish that a previously exposed appliance was not compromised. For attacker-reachable ISE and ISE-PIC systems, remediation should be paired with compromise-focused investigation using evidence retained outside the appliance wherever possible.
For a structured approach to vulnerability management, monitoring, and incident readiness, see our guide to Managed Cybersecurity for GCC SMBs.
Cyberactics Security Team
Managed Security Services
We help SMBs across Jordan, Saudi Arabia, Oman, and the UAE respond to active threats and validate exposure across their environments.
Talk to an incident response engineer
Book a 30-minute call and we'll walk through exposure assessment, patch validation, and post-remediation investigation for your environment.



