“ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls,” Landon Rice, senior exploit developer at VulnCheck, told CyberScoop.
CVE-2026-76460: authentication bypass in Cisco Identity Services Engine
Cisco disclosed CVE-2026-76460 on Wednesday as a maximum-severity zero-day in an API of Cisco Identity Services Engine (ISE). According to Cisco, the defect allows a remote attacker to bypass authentication and gain full control of an affected device. Cisco said the vulnerability was exploited before the vendor disclosed and patched the flaw; the company discovered the vulnerability during a technical support case but did not disclose how many organizations may have been compromised or when the first exploitation occurred.
Cisco’s advisory, patching and indicators
In its public statements Cisco said, “Cisco is aware of active exploitation of this vulnerability. We strongly recommend customers upgrade to available fixed software and follow guidance in the advisory.” Cisco published indicators of compromise to help customers hunt for attempted exploitation and noted there are no workarounds for the vulnerability. The vendor has released fixed software and urged customers to upgrade.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadCISA listing, prior ISE exploitation, and attribution
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its known exploited vulnerabilities catalog shortly after Cisco’s disclosure. Researchers have not attributed attacks involving CVE-2026-76460 to any named group or threat actor, but VulnCheck’s Landon Rice emphasized that Cisco ISE vulnerabilities have been targeted repeatedly: multiple vulnerabilities affecting the product have been exploited since June 2025, including CVE-2025-20337 and CVE-2025-20281. The latest zero-day and the pair of defects disclosed in summer 2025 were all rated critical with the highest severity score of 10.
Consecutive CVEs and an unrelated email-gateway zero-day
The disclosure of CVE-2026-76460 came two days after Cisco disclosed CVE-2026-76461, an actively exploited zero-day in Cisco Secure Email Gateway. Although the two CVEs have consecutive identifiers, both Rice and a Cisco spokesperson said the numbering reflects CVE assignment order rather than a technical relationship: “CVEs are assigned on a first-come, first-served basis, so consecutive numbering reflects assignment order rather than any relationship between the issues. CVE-2026-76460 and CVE-2026-76461 affect different codebases,” the Cisco spokesperson said. Rice characterized the issues as affecting different products and different vulnerability classes with no relation.
How technologists, CISA, and affected enterprises are responding
- Technologists and security teams: Teams running Cisco ISE will be expected to apply the fixed software that Cisco released and to use the published indicators of compromise to hunt for evidence of exploitation. Rice’s warning that a compromised ISE can let an attacker modify network access policy, extract stored credentials and delete logs creates an immediate detection priority: if logs have been deleted, teams will need to rely on external logging, network telemetry and the IOCs Cisco published.
- CISA and federal/regulated entities: CISA’s rapid inclusion of CVE-2026-76460 on its known exploited vulnerabilities catalog signals priority attention for agencies and organizations following that catalog. That listing typically raises the visibility of the vulnerability across federal and critical-infrastructure customers and accelerates patch and mitigation timelines.
- Affected enterprises and procurement leaders: Organizations that use ISE will confront both an urgent patch task and a procurement question: ISE has been exploited repeatedly since June 2025 (including the two CVEs rated 10 mentioned above), so buyers and asset owners must weigh the operational need for rapid patching against the fact that Cisco reported no workarounds and that detection may require active hunting.
Two consecutive, actively exploited zero-days affecting different Cisco products in the span of days tightens the pressure on defenders: upgrade where fixed software is available, hunt with the indicators Cisco published, and assume that an attacker who gained root on an ISE appliance could alter policy, extract credentials and obfuscate activity by deleting logs. With no attribution released and prior ISE defects exploited since June 2025, the unanswered question is whether recurring exploitation of ISE will continue to produce high-severity, pre-disclosure compromises.




