Cisco Vulnerability CVE-2026-76460 Allows Unauthenticated Access with Root Privileges
Cisco has disclosed a critical vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The bug, tracked as CVE-2026-76460, allows an unauthenticated attacker to bypass authentication and gain access to the management interface with root privileges. This could give attackers broad control over affected devices and allow them to hide or remove evidence of compromise.
Cisco has confirmed that the vulnerability is being actively exploited, and the US Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities catalog. The vulnerability affects all versions of Cisco ISE and ISE-PIC, regardless of configuration, and does not require credentials or user interaction.
Cisco warns that attackers may use this vulnerability to obtain command execution with root privileges, which could lead to unauthorized access to the management interface, changes to device settings or network-access controls, exposure of sensitive configuration or operational information, removal or concealment of evidence in device logs, and disruption to identity and network-access services.
Organizations affected by this vulnerability should patch every affected node as soon as possible. This can be done by upgrading Cisco ISE and ISE-PIC to the appropriate fixed release: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4.