"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said.
Cisco's description of CVE-2026-76460
Cisco has disclosed a maximum-severity zero-day tracked as CVE-2026-76460 (CVSS score: 10.0) that allows an unauthenticated, remote attacker to bypass authentication on Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). According to Cisco, "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."
Cisco also warned it is "aware of active exploitation of this vulnerability," but the company did not share any details on the nature of the attacks exploiting the flaw, or who is behind them.
Affected ISE and ISE‑PIC releases and available fixes
- ISE 3.1 — Fixed in 3.1 Patch 12
- ISE 3.2 — Fixed in 3.2 Patch 11
- ISE 3.3 — Fixed in 3.3 Patch 12
- ISE 3.4 — Fixed in 3.4 Patch 7
- ISE 3.51 — Fixed in 3.5 Patch 4
Cisco emphasised there are no workarounds. As a mitigation, the company suggested using infrastructure access control lists (iACLs) to "allow only required management and control plane traffic that is destined to the affected device."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDetection guidance, indicators of compromise, and response steps
For immediate detection, Cisco recommended reviewing the ISE access log for suspicious usernames and provided a direct command to search for unexpected accounts across nodes in distributed deployments. Cisco advised administrators to run:
admin#show logging application ise-kong/access.log | include dummyuser
"The presence of any entry in the command output likely points to malicious activity," Cisco said. If exploitation is detected, Cisco advises re-imaging affected nodes and restoring from configuration backups if needed. The company warned that "Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges," and cautioned that "evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors."
CISA listing and the federal patching requirement
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026. That designation requires Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
The CISA KEV listing makes the vulnerability a compliance-driven priority for FCEB agencies and signals heightened scrutiny for organizations that support or integrate with federal systems.
Related Cisco advisories and the wider set of fixes
This disclosure follows a separate Cisco advisory about an active exploit for AsyncOS Software on Cisco Secure Email Gateway (CVE-2026-76461, CVSS 9.8). On the same release cycle, Cisco issued fixes for 77 new CVEs across its portfolio: 41 affect ISE and 28 affect the Secure Firewall lineup.
The vendor grouped a number of high-severity issues by impact type. Examples called out in Cisco's advisory include multiple ISE vulnerabilities that could allow authenticated attackers with administrative credentials to execute arbitrary commands (CVE-2026-20176, CVSS 9.9; CVE-2026-20211, CVSS 9.1; CVE-2026-20307, CVSS 9.1) and several authentication- and execution-related flaws with CVSS scores at or near maximum (CVE-2026-76423 through CVE-2026-76428, CVE-2026-20130, CVE-2026-20192 and others). Cisco also listed numerous high-severity issues affecting Secure Firewall Adaptive Security Appliance (ASA), Threat Defense (FTD), and Management Center (FMC) products.
What this means for FCEB agencies, security teams, and affected enterprises
- FCEB agencies: The CISA KEV listing requires FCEB agencies to install the fixes by September 19, 2026, making patch deployment a near-term compliance obligation.
- Security teams and technologists: Teams should prioritise upgrading affected ISE and ISE‑PIC instances to the listed patched releases, implement iACLs where feasible to limit management-plane exposure, and audit access.log across all nodes using the Cisco-provided command to search for suspicious usernames.
- Affected enterprises and procurement leaders: Organisations that run Cisco ISE or ISE‑PIC should assess their inventory against the fixed versions and plan urgent patch cycles, recognising Cisco's warning that successful exploitation can yield root command execution and may remove forensic traces.
Cisco's advisory leaves a narrow, concrete worklist: identify affected ISE/ISE‑PIC instances, apply the published patches, and scan logs for the telltale "dummyuser" sign of compromise. With the vulnerability rated CVSS 10.0, active exploitation observed by the vendor, and a federal remediation deadline already set, the clock is short and the technical stakes are high.




