Cisco ISE Hit by Critical Vulnerability Allowing Unauthenticated Attacks
Cisco has issued a critical security update to address a maximum-severity vulnerability found in its Identity Services Engine (ISE). The flaw, tracked as CVE-2026-76460, allows an unauthenticated attacker to bypass authentication and gain unauthorized access to the affected device. The bug affects Cisco ISE and Cisco ISE Passive Identity Connector, regardless of device configuration.
Cisco's Product Security Incident Response Team (PSIRT) is aware of active exploitation and urges customers to upgrade to a fixed software release as soon as possible. There are no workarounds available for this flaw, making patching the only solution. The CISA has added the bug to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch or disable ISE by September 19, 2026.
Cisco has shared Indicators of Compromise (IoC) and advised defenders to hunt for suspicious usernames in access.log files on every node. In case of a breach, the company recommends re-imaging nodes and restoring them from backups.