Cisco Issues Emergency Security Updates for Critical ISE Vulnerability
Cisco has released emergency security updates to address a critical vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw, tracked as CVE-2026-76460, allows an unauthenticated remote attacker to bypass authentication and gain unauthorized access to a vulnerable device.
The vulnerability resides in an ISE API endpoint that does not enforce sufficient authentication controls. An attacker can send a specially crafted request to the affected API and bypass the web-based management interface without possessing valid administrator credentials.
Cisco warns that successful exploitation may ultimately provide attackers with command execution as root, allowing them to alter the system and potentially remove or conceal evidence of compromise. The company has not publicly disclosed the precise technical sequence by which the initial API authentication bypass progresses to root command execution.
Organizations are advised to upgrade every affected ISE or ISE-PIC node to the appropriate patched release as an emergency action. Cisco provides a temporary exposure-reduction measure for organizations that cannot upgrade immediately: infrastructure access control lists can restrict management and control-plane traffic destined for the affected device to explicitly trusted systems.