Your network admission-control brain just got a Saturday deadline. Cisco Identity Services Engine has a maximum-severity API authentication bypass that can land root on the appliance — and CISA wants federal agencies patched by September 19, 2026.
If ISE or ISE-PIC management is reachable from anywhere wider than a jump host, this is tonight’s work — not next week’s change window.
What happened
On September 16, 2026, Cisco disclosed an incorrect use of privileged APIs on an ISE / ISE-PIC endpoint. An unauthenticated remote attacker can send a crafted request, bypass the web-based management interface, and — per Cisco — may obtain command execution with root privileges.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Cisco PSIRT is aware of active exploitation. There are no workarounds; infrastructure ACLs that lock the management interface to trusted sources are the only interim control. CISA added the bug to the Known Exploited Vulnerabilities catalog the same day, with a federal due date of September 19, 2026 and forensic triage required under BOD 26-04.
Why it matters
ISE is the NAC brain: RADIUS/TACACS+, profiling, and policy over who gets on the network and at what privilege. Root on that box is a pivot primitive against every downstream authenticated segment — not a single-appliance outage.
Cisco warns a root attacker can remove or hide local evidence and strongly recommends re-imaging compromised nodes rather than trusting in-place cleanup. Release 3.0 is end-of-support with no fix — migration is the only path.
What to do first
- Upgrade every ISE and ISE-PIC node to a fixed build: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4. Confirm the patch level on each node.
- Immediately restrict management UI/API access with iACLs to trusted admin networks/VPN only.
- Hunt
access.log/ ise-kong API gateway logs on every node of a distributed deployment for suspicious usernames (Cisco cites patterns such as reviewingise-kong/access.log). - If compromise looks likely: preserve forensics, re-image from a known-good config backup, rotate AD / RADIUS / TACACS+ secrets and admin credentials, and audit recent policy and identity-source changes.
- Migrate any remaining 3.0 deployments — there is no patch train.
- Treat the September 16 ISE hardening release as a full surface trim (sibling critical flaws shipped the same day), not a one-CVE cherry-pick.
Details
- CVE: CVE-2026-76460 (CVSS 10.0, CWE-648)
- Product: Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), any configuration
- Class: Incorrect use of privileged APIs → unauthenticated management bypass; may yield root command execution
- KEV: Added 2026-09-16; federal due 2026-09-19; forensic triage under BOD 26-04
- Workarounds: None (iACL management restriction only)
- Fixed: 3.1 P12 / 3.2 P11 / 3.3 P12 / 3.4 P7 / 3.5 P4; 3.0 EoS = no fix
- Advisory: cisco-sa-ISE-ABP-VNSW7Tn5
Hunt / verify
- Confirm installed patch level matches a fixed release on every PAN/PSN/MnT node.
- Review
access.logand support-bundle API gateway logs for unexpected usernames and pre-auth API hits. - Diff admin accounts, external identity sources, and recent policy pushes against a known-good baseline.
- Treat local IoCs as incomplete if root was possible — lean on external firewall/proxy and AAA logs.
Sources
- Cisco PSIRT: ISE Incorrect Use of Privileged APIs (CVE-2026-76460)
- CISA: Adds Two KEVs (Sep 16, 2026) — includes CVE-2026-76460
- CISA Known Exploited Vulnerabilities Catalog — due 2026-09-19
- The Hacker News: Cisco ISE zero-day auth bypass
- SecurityWeek: Active exploitation triggers ISE emergency patch
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.