SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityCiscoAccess management

Cve-2026-76460: cisco ise and ise-pic hit by an exploited authentication bypass

Cisco confirms active exploitation of CVE-2026-76460, a critical API flaw in ISE and ISE-PIC. Affected releases, fixes and checks to perform.

By Soclyde Team

An empty network room with an access-control rack and an unplugged management cable after an incident

In summary

  • CVE-2026-76460 lets an unauthenticated remote attacker bypass authentication on a Cisco ISE API endpoint and reach the web-based management interface.
  • Cisco confirms active exploitation; ISE and ISE-PIC releases 3.1 through 3.5 are affected, with no workaround available.
  • Apply the matching fix, restrict management access and review logs before treating the incident as closed.

Explore next

Soclyde resources

Article contents

On September 16, 2026, Cisco published a critical advisory for CVE-2026-76460, an authentication vulnerability in a Cisco Identity Services Engine (ISE) API. An unauthenticated remote attacker can send a crafted request, bypass the web-based management interface and access the device. Cisco says the vulnerability is being actively exploited.

ISE and its ISE Passive Identity Connector (ISE-PIC) component enforce network-access policies and handle identity information. A console of this kind is a sensitive control point: the priority is to patch affected nodes, then check whether the management interface was used before the update.

What the flaw changes for Cisco ISE

CVE-2026-76460 is caused by insufficient authentication control on an API endpoint. Cisco’s documented scenario requires neither prior privileges nor user interaction: a crafted request can let a remote attacker pass the protection around the web-based management interface.

The vulnerability has a CVSS score of 10.0, with potential impact to confidentiality, integrity and availability. That score does not mean every instance was compromised; it means the documented attack path requires neither a valid account nor action by the victim.

Affected releases and fixes

Cisco lists Cisco ISE and ISE-PIC releases 3.1, 3.2, 3.3, 3.4 and 3.5 as affected. The first fixed patches are patch 12 for 3.1, 11 for 3.2, 12 for 3.3, 7 for 3.4 and 4 for 3.5. A 3.0 installation, which has reached end of software maintenance, should migrate to a supported release.

There is no workaround that replaces the update. If patching cannot happen immediately, Singapore’s Cyber Security Agency recommends restricting management and control-plane traffic destined for the device with infrastructure ACLs, allowing only required access. This reduces exposure but does not fix the vulnerability.

Why active exploitation requires a review

Cisco says its PSIRT is aware of active exploitation of CVE-2026-76460. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 16, providing an additional independent signal for prioritising exposed systems.

The practical consequence is straightforward: installing the fix alone does not prove that no access occurred. An ISE node reachable from an uncontrolled network should be reviewed, without claiming that it was compromised when there is no evidence.

Checks for every node

Start by inventorying the versions and access paths for every ISE and ISE-PIC node, then apply the matching Cisco fix. Preserve logs before any action that could overwrite them and compare the exposure window with known administration events.

The Cyber Security Agency of Singapore recommends reviewing access.log and looking for suspicious usernames, including in the logs of every node in a distributed deployment. If malicious activity is suspected, the agency recommends re-imaging affected nodes and restoring a configuration backup if needed. Specialist investigation is preferable to a simple password reset when access to the interface is confirmed.

Protecting the access around ISE

ISE sits in the middle of decisions about network connections and identities. After an exposure, inventory administrator accounts, service accounts, certificates, keys and secrets used by integrations. Rotate anything that may have been accessed or reused elsewhere, coordinating the change with log analysis.

End users cannot patch an appliance they do not administer. But if an administrator, supplier or service password was reused for email or another application, replace it everywhere it was used and be wary of urgent validation requests received after the incident.

The Soclyde connection

Soclyde does not patch Cisco ISE and cannot determine whether an appliance was compromised. Its role is around the access reviews that may follow: generating unique secrets, keeping them in local-first encrypted vaults and avoiding copied passwords in tickets, configuration exports or email.

That separation helps limit reuse when a network device or service account is affected. It complements Cisco patching, network restriction, log retention and incident response; it does not replace them.

Key takeaways

CVE-2026-76460 is a critical authentication bypass in Cisco ISE and ISE-PIC, actively exploited according to Cisco. Releases 3.1 through 3.5 have dedicated fixes, while a 3.0 installation must be migrated. Apply the update, immediately reduce management exposure and review every node’s logs before closing the issue.

To structure access rotation after an exposure, read the secure password generator guide or contact Soclyde.

Frequently asked questions

What does CVE-2026-76460 allow?

The flaw is caused by insufficient authentication control on a Cisco Identity Services Engine API endpoint. An unauthenticated remote attacker can send a crafted request, bypass the web management interface and gain unauthorized access to the device.

Which Cisco ISE and ISE-PIC releases need to be fixed?

Cisco lists releases 3.1, 3.2, 3.3, 3.4 and 3.5 as affected. The first fixed patches are 12, 11, 12, 7 and 4 respectively. Release 3.0 should be migrated to a supported release.

What should I check if the fix is not installed yet?

Use infrastructure ACLs to limit traffic to the management interface and allow only required access. Then review each node’s access.log for suspicious usernames; if malicious activity is possible, isolate the nodes and engage incident response.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading