Cisco ISE Zero-Day Vulnerability Allows Unauthenticated Remote Attackers
A critical authentication-bypass vulnerability has been discovered in Cisco's Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The issue, identified as CVE-2026-76460, allows an unauthenticated remote attacker to bypass authentication on the web-based management interface via a crafted request to the affected API. This could potentially lead to command execution with root privileges.
Cisco has confirmed that active exploitation of this vulnerability is underway, and the CISA (Cybersecurity and Infrastructure Security Agency) has added it to their Known Exploited Vulnerabilities catalog. The agency has also set a federal remediation due date of September 19, 2026, and requires forensic triage for affected systems.
The vulnerability affects all versions of Cisco ISE, regardless of device configuration, and there are no workarounds available to address the issue. Temporary mitigation involves limiting management/control-plane traffic using infrastructure ACLs (iACLs). It is recommended that users upgrade to a fixed release as soon as possible, as ISE 3.0 has reached End of Software Maintenance.
Cisco and CISA have provided guidance on how to remediate the issue, including reviewing access logs and external network/firewall logs for suspicious activity. Users are advised to be cautious when dealing with potential indicators of compromise, as root may allow on-box evidence removal.