The flaw received the maximum CVSS score of 10.0.
CVE-2026-76460: an authentication bypass that yields root
Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass that affects Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE‑PIC). Cisco says insufficient authentication controls on an API endpoint allow an unauthenticated remote attacker to send a crafted request that bypasses the product’s web-based management interface. No credentials or user interaction are required, and Cisco says vulnerable versions of ISE and ISE‑PIC are affected regardless of configuration. Successful exploitation can give command execution with root privileges.
Active exploitation, CISA listing, and what Cisco has told customers
Cisco’s Product Security Incident Response Team said it was “aware of active exploitation” and urged customers to install the fixes immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE‑2026‑76460 to its Known Exploited Vulnerabilities catalog. Cisco has not disclosed who is exploiting the vulnerability, how long the attacks have been underway, or what intruders have done after gaining access.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnical scope, detection guidance, and post‑compromise risk
The vulnerable code sits in an API within Cisco ISE, the company’s network access control platform. Cisco warned that root access could allow attackers to remove or conceal traces of an intrusion, “complicating efforts to determine whether an appliance had been breached.” As part of detection guidance, Cisco advised administrators to review ISE access logs for suspicious usernames on every node in a distributed deployment and to check network and firewall logs held outside the affected device for signs of unexpected uploads or downloads.
Remediation: patches, mitigations, and unsupported releases
Cisco said there is no workaround. As a temporary mitigation, infrastructure access control lists can be used to restrict management and control‑plane traffic reaching affected systems. Permanent fixes are available in ISE and ISE‑PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. Cisco also noted that ISE 3.0 has reached the end of software maintenance, and customers running it must migrate to a supported release.
If administrators find evidence of possible exploitation, Cisco “strongly recommends” reimaging affected nodes and restoring their configurations from backup if necessary.
How technologists, affected enterprises, and policymakers are likely to respond
- Technologists and security teams: Expect immediate prioritization of the listed ISE and ISE‑PIC patches and temporary ACLs to limit management plane access. Teams will also need to hunt for signs of compromise in access logs and external network/firewall logs given Cisco’s warning about attackers concealing traces.
- Affected enterprises and procurement leaders: Organizations running ISE should inventory versions in use (noting that all vulnerable versions are affected regardless of configuration), accelerate migrations off ISE 3.0 where relevant, and prepare procedures for reimaging and restoring nodes if exploitation is detected.
- Policymakers and regulators: With CISA adding the flaw to its Known Exploited Vulnerabilities catalog, compliance and incident‑notification frameworks that reference that catalog will come into play; regulators and oversight entities monitoring critical infrastructure may press for rapid mitigation and reporting.
Context within a busy patching window and outstanding questions
The advisory arrives days after Cisco disclosed another actively exploited critical vulnerability, CVE‑2026‑76461, affecting Secure Email Gateway and Secure Email and Web Manager appliances — a 9.8‑rated bug that also could lead to root access and, Cisco warned, allow attackers to cover their tracks. Cisco published a substantial batch of other ISE advisories the same day: two carried maximum CVSS scores of 10.0 and a separate trio of remote code execution flaws scored as high as 9.9. For administrators responsible for Cisco equipment, the company warned that September is shaping up to be an intense patching month.
What remains unanswered — and what Cisco explicitly declined to disclose — is who is exploiting CVE‑2026‑76460, how long attacks have been underway, and what, if anything, intruders have done after gaining access. Those questions will determine whether the effort is purely preventive or also restorative for organizations that find indicators of compromise.




