Cisco ISE Hit with Authentication Bypass Bug
Cisco has confirmed that its Identity Services Engine (ISE) is vulnerable to an authentication bypass bug, CVE-2026-76460. This flaw allows unauthenticated attackers to access the affected device's management interface by sending a crafted request to a specific API endpoint.
The Cisco ISE platform is used for identity-based network access control and policy enforcement. It checks users' identities, profiles devices, and monitors their security posture before granting access. However, the vulnerability in question means that attackers can bypass these controls and gain unauthorized access to the affected device.
Cisco has provided indicators of compromise and advised customers to review their logs for suspicious activity. They should also re-image affected nodes and restore from configuration backups if necessary. The company has fixed the issue in various releases, including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.