Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco Discloses Actively Exploited Zero-Day in Identity Services Engine

Network operations center with equipment and servers, and a single unoccupied laptop workstation in the foreground.

"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco wrote, describing a flaw that attackers are already exploiting to bypass authentication on its Identity Services Engine.

Cisco PSIRT alerts and the immediate patch response

Cisco has released security updates to address a maximum-severity vulnerability in its Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE‑PIC). The company’s Product Security Incident Response Team (PSIRT) warned customers that CVE‑2026‑76460 is being actively exploited in the wild and "strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability." Cisco described the bug as allowing an attacker to gain unauthorized access by bypassing the web-based management interface.

How CVE‑2026‑76460 works against ISE and ISE‑PIC

The flaw, tracked as CVE‑2026‑76460, lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine and Cisco ISE Passive Identity Connector "regardless of configuration." Cisco explained that an attacker can exploit the issue by sending a crafted request to an affected API endpoint. A successful exploit could enable unauthorized access to the affected device and lead to command execution with root privileges.

Cisco's wider set of September fixes and apparent status notes

In a related advisory, Cisco said it patched a second maximum‑severity authentication bypass flaw, CVE‑2026‑76423, and five other critical security issues in Cisco ISE and Cisco ISE‑PIC. Those additional tracked vulnerabilities were listed as CVE‑2026‑76460, CVE‑2026‑20176, CVE‑2026‑20211, CVE‑2026‑20307, and CVE‑2026‑20284; Cisco noted these had not yet been flagged as actively exploited in its advisory. Separately, PSIRT specifically reported active exploitation of CVE‑2026‑76460 and urged immediate upgrading to fixed releases.

CISA's three-day directive and the Known Exploited Vulnerabilities catalog

The Cybersecurity and Infrastructure Security Agency ordered federal agencies to patch systems against CVE‑2026‑76460 within three days after adding it to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. That inclusion triggered the tightened federal remediation timeline demanded for KEV entries.

Indicators of compromise and recommended remediation steps

Cisco provided indicators of compromise and concrete response steps for security teams. Administrators were told to examine access.log files on every node for suspicious usernames and to cross‑check firewall and network logs for signs of suspicious activity, including downloads and uploads to external or malicious IP addresses. Because attackers who obtain root privileges can remove traces of their activity, Cisco "strongly" recommended re‑imaging compromised nodes and restoring them from backups where malicious activity is suspected. The company also warned that no workarounds exist; applying the supplied security updates is the only recommended course of action.

What this means for IT administrators, federal agencies, and security teams

  • IT administrators running Cisco ISE or ISE‑PIC: prioritize installing the fixed software releases immediately, inspect access.log files for suspicious usernames on every node, and be prepared to re‑image and restore from backups if evidence of compromise appears.
  • Federal agencies subject to CISA directives: act within the three‑day remediation window set by CISA after CVE‑2026‑76460 was added to the KEV Catalog — the agency’s order makes patching mandatory on that timeline for affected federal systems.
  • Security operations teams and incident responders: correlate firewall and network logs for uploads and downloads to external addresses, assume logs may have been tampered with if root execution is suspected, and use Cisco’s published indicators of compromise as a starting point for triage.

This advisory follows a July 2025 incident in which threat actors exploited a different Cisco ISE zero‑day, CVE‑2025‑20337, to deploy a custom "IdentityAuditAction" web shell disguised as a legitimate ISE component. Over the last five years, CISA has tagged 99 Cisco product flaws as actively exploited, including seven associated with ransomware attacks — a record that underscores the operational urgency behind Cisco’s update and CISA’s three‑day order.

The immediate choices are starkly limited: because Cisco reports no workarounds, patching is the only recommended defense, and re‑imaging is recommended where compromise is suspected. For organizations that rely on ISE for centralized policy and Zero Trust enforcement, the path forward is clear — update quickly, verify logs, and assume an aggressive cleanup posture until nodes can be validated as clean.

Source: BleepingComputer