On September 16, 2026, Cisco published a critical advisory for CVE-2026-76460, an authentication vulnerability in a Cisco Identity Services Engine (ISE) API. An unauthenticated remote attacker can send a crafted request, bypass the web-based management interface and access the device. Cisco says the vulnerability is being actively exploited.
ISE and its ISE Passive Identity Connector (ISE-PIC) component enforce network-access policies and handle identity information. A console of this kind is a sensitive control point: the priority is to patch affected nodes, then check whether the management interface was used before the update.
What the flaw changes for Cisco ISE
CVE-2026-76460 is caused by insufficient authentication control on an API endpoint. Cisco’s documented scenario requires neither prior privileges nor user interaction: a crafted request can let a remote attacker pass the protection around the web-based management interface.
The vulnerability has a CVSS score of 10.0, with potential impact to confidentiality, integrity and availability. That score does not mean every instance was compromised; it means the documented attack path requires neither a valid account nor action by the victim.
Affected releases and fixes
Cisco lists Cisco ISE and ISE-PIC releases 3.1, 3.2, 3.3, 3.4 and 3.5 as affected. The first fixed patches are patch 12 for 3.1, 11 for 3.2, 12 for 3.3, 7 for 3.4 and 4 for 3.5. A 3.0 installation, which has reached end of software maintenance, should migrate to a supported release.
There is no workaround that replaces the update. If patching cannot happen immediately, Singapore’s Cyber Security Agency recommends restricting management and control-plane traffic destined for the device with infrastructure ACLs, allowing only required access. This reduces exposure but does not fix the vulnerability.
Why active exploitation requires a review
Cisco says its PSIRT is aware of active exploitation of CVE-2026-76460. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 16, providing an additional independent signal for prioritising exposed systems.
The practical consequence is straightforward: installing the fix alone does not prove that no access occurred. An ISE node reachable from an uncontrolled network should be reviewed, without claiming that it was compromised when there is no evidence.
Checks for every node
Start by inventorying the versions and access paths for every ISE and ISE-PIC node, then apply the matching Cisco fix. Preserve logs before any action that could overwrite them and compare the exposure window with known administration events.
The Cyber Security Agency of Singapore recommends reviewing access.log and looking for suspicious usernames, including in the logs of every node in a distributed deployment. If malicious activity is suspected, the agency recommends re-imaging affected nodes and restoring a configuration backup if needed. Specialist investigation is preferable to a simple password reset when access to the interface is confirmed.
Protecting the access around ISE
ISE sits in the middle of decisions about network connections and identities. After an exposure, inventory administrator accounts, service accounts, certificates, keys and secrets used by integrations. Rotate anything that may have been accessed or reused elsewhere, coordinating the change with log analysis.
End users cannot patch an appliance they do not administer. But if an administrator, supplier or service password was reused for email or another application, replace it everywhere it was used and be wary of urgent validation requests received after the incident.
The Soclyde connection
Soclyde does not patch Cisco ISE and cannot determine whether an appliance was compromised. Its role is around the access reviews that may follow: generating unique secrets, keeping them in local-first encrypted vaults and avoiding copied passwords in tickets, configuration exports or email.
That separation helps limit reuse when a network device or service account is affected. It complements Cisco patching, network restriction, log retention and incident response; it does not replace them.
Key takeaways
CVE-2026-76460 is a critical authentication bypass in Cisco ISE and ISE-PIC, actively exploited according to Cisco. Releases 3.1 through 3.5 have dedicated fixes, while a 3.0 installation must be migrated. Apply the update, immediately reduce management exposure and review every node’s logs before closing the issue.
To structure access rotation after an exposure, read the secure password generator guide or contact Soclyde.



