Exploits

Cisco ISE Authentication Bypass Under Active Attack

Published  ·  5 min read

Cisco has a new problem. And it's a big one.

A maximum-severity flaw in Identity Services Engine is being actively exploited. The bug lets an unauthenticated attacker bypass authentication entirely. No credentials. No login. Just a crafted request.

The vulnerability is CVE-2026-76460. CVSS score: 10.0. That's the highest possible. Cisco published the advisory and CISA added it to the Known Exploited Vulnerabilities catalog the next day.

Let me break down what's happening.

Quick Summary

What

Details

Vulnerability

CVE-2026-76460

CVSS

10.0

Affected

Cisco ISE and ISE-PIC

Impact

Unauthenticated auth bypass → root

Status

Actively exploited

CISA Deadline

September 19, 2026

What Is the Bug?

It's an insufficient authentication control on an API endpoint. That's the technical description. In plain English: the API doesn't check who you are properly. So you can pretend to be someone else.

"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."

Once in, the attacker can execute commands with root privileges. That's the keys to the kingdom.

Who's Affected?

Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC). Both are affected regardless of configuration.

ISE is a big deal. It's the system that controls network access. It decides who gets on the network, what they can access, and how. If someone owns ISE, they own identity.

Fixed versions:

Release

Fixed In

3.1

Patch 12

3.2

Patch 11

3.3

Patch 12

3.4

Patch 7

3.5

Patch 4

No workarounds. You have to update. Cisco says you can use infrastructure access control lists (iACLs) to restrict traffic as a mitigation, but that's not a fix.

How to Check for Compromise

Cisco shared some indicators. Here's what to do.

1. Check your access log.

Look for suspicious usernames. Cisco provided a command:

admin# show logging application ise-kong/access.log | include dummyuser

If anything shows up, that's a red flag. The username dummyuser is a known indicator.

2. Check every node.

If your ISE deployment is distributed, check the logs on every node. Don't assume one is clean just because others are.

3. If you find something, re-image.

Cisco says if you detect malicious activity, re-image the affected nodes. Restore from configuration backup if needed. That's a serious step, but root-level compromise means you can't trust the system.

4. Check outside the device.

Because the attacker gets root, they can hide evidence. Logs can be deleted. Traces can be erased. So look at your network logs and firewall logs too. Look for unusual outbound connections.

The CISA Deadline

CISA added CVE-2026-76460 to the KEV catalog on September 16, 2026. Federal Civilian Executive Branch agencies have until September 19, 2026, to patch.

That's a three-day window. Short. But that's what a CVSS 10.0 with active exploitation looks like.

The Bigger Picture: 77 New CVEs

The ISE bug is the headline. But Cisco also released fixes for a lot of other stuff. Seventy-seven new CVEs on Wednesday. Forty-one affect ISE. Twenty-eight affect the Secure Firewall portfolio.

Here's a sample of the critical ones:

CVE

CVSS

Product

What It Does

CVE-2026-76423

10.0

ISE/ISE-PIC

REST API bypass, RCE, SQLi, XXE

CVE-2026-20130

10.0

ISE/ISE-PIC

Command injection, auth bypass

CVE-2026-20192

10.0

ISE/ISE-PIC

Command injection, auth bypass

CVE-2026-20242

9.8

FMC

Unauthenticated root command execution

CVE-2026-20322

9.9

Nexus Dashboard

Command injection, auth bypass

CVE-2026-20324

9.9

FMC

Authenticated root command execution

CVE-2026-20353

9.8

Secure Email Gateway

Path traversal, auth bypass, command injection

Some of these require authentication. Some don't. Some are hardening measures from Cisco's internal review. But all of them are worth patching.

What You Should Do

1. Patch immediately.

Update ISE and ISE-PIC to the fixed versions. Check every node in your deployment. Don't skip any.

2. Check your logs.

Run the dummyuser command. Search for suspicious usernames in access.log file. Check all nodes.

3. Review network and firewall logs.

Because root-level attackers can hide evidence, look outside the device. Check for unusual outbound connections. Look for unexpected uploads.

4. Consider using iACLs.

Where you are unable to apply patches immediately, make use of infrastructure ACLs in order to limit access to the ISE device. Allow only what's necessary.

5. Re-image if compromised.

If you find indicators, re-image the affected nodes. Restore from backup. Don't try to clean it. Root compromise means the system can't be trusted.

6. Check the other CVEs.

Review the full list of 77 CVEs. If you run Secure Firewall, Nexus Dashboard, or other Cisco products, check for applicable patches.

The Bottom Line

Cisco ISE has a CVSS 10.0 authentication bypass. CVE-2026-76460. Unauthenticated attacker gets root. It's being actively exploited. CISA gave federal agencies three days to patch. If you run ISE, patch now. Check your logs. Re-image if you find something.

Quick Reference:

Key Point

Detail

Vulnerability

CVE-2026-76460

CVSS

10.0

Affected

Cisco ISE and ISE-PIC

Impact

Unauthenticated auth bypass → root

Fixed Versions

3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4

CISA Deadline

September 19, 2026

IoC Command

show logging application ise-kong/access.log | include dummyuser

What to Do:

  • Patch immediately
  • Check access.log for dummyuser
  • Review network and firewall logs
  • Use iACLs as a temporary mitigation
  • Re-image if compromised
  • Check the other 77 CVEs

FAQ Section

What is CVE-2026-76460?

A maximum-severity vulnerability in Cisco ISE. It allows an unauthenticated attacker to bypass authentication and gain root access on the affected device.

Which products are affected?

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC).

Is it being exploited?

Yes. Cisco says it's aware of active exploitation. CISA added it to the KEV catalog.

How do I check if I'm compromised?

Run show logging application ise-kong/access.log | include dummyuser. If you see entries, that's malicious activity. Check every node in a distributed deployment.

What should I do if compromised?

Re-image the affected nodes. Restore from configuration backup. Root compromise means you can't trust the system.

What if I can't patch right away?

Use infrastructure access control lists (iACLs) to restrict traffic to the ISE device. That's a mitigation, not a fix.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067