Cisco has released emergency patches for a maximum-severity vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that is being actively exploited in the wild. ISE is widely deployed as a centralized policy platform for managing endpoints, users, and device access, often as part of Zero Trust network architectures, making the flaw especially attractive to attackers seeking a foothold inside enterprise networks.

What the flaw does

Tracked as CVE-2026-76460 and rated CVSS 10.0, the vulnerability stems from insufficient authentication control on an API endpoint. According to Cisco, a remote, unauthenticated attacker can send a specially crafted request to the affected API and bypass the web-based management interface entirely, gaining unauthorized access to the device regardless of how it is configured.

Cisco’s Product Security Incident Response Team (PSIRT) confirmed active exploitation and said attackers have obtained command execution with root privileges on compromised systems. The company warned that attackers may attempt to erase evidence of exploitation, so administrators should not rely solely on device logs when investigating potential compromise.

No workarounds, patch now

Cisco said there are no mitigations available aside from upgrading to a fixed release. Affected versions and their first fixed releases are:

  • 3.1: Patch 12
  • 3.2: Patch 11
  • 3.3: Patch 12
  • 3.4: Patch 7
  • 3.5: Patch 4

Cisco has published indicators of compromise and urged security teams to review access.log files on every ISE node for suspicious usernames, as well as firewall and network logs for unusual uploads or downloads to external IP addresses. If malicious activity is confirmed, Cisco strongly recommends re-imaging affected nodes and restoring them from clean backups rather than attempting in-place remediation.

Part of a larger patch batch

The disclosure follows a separate maximum-severity authentication bypass, CVE-2026-76423, along with five other critical vulnerabilities (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) that Cisco patched in ISE and ISE-PIC around the same time. None of these additional flaws have been flagged as actively exploited so far.

CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days. This marks the second ISE zero-day exploited in the wild in roughly a year, following a July 2025 remote code execution flaw (CVE-2025-20337) that attackers used to deploy a custom web shell disguised as a legitimate ISE component. CISA has tagged 99 Cisco product vulnerabilities as actively exploited over the past five years.