Cisco ISE CVE-2026-76460: Unauth Management Bypass to Root — KEV Due September 19

By George Bailey   Published: 09/17/26   Updated: 09/17/26   3 min read

Your network admission-control brain just got a Saturday deadline. Cisco Identity Services Engine has a maximum-severity API authentication bypass that can land root on the appliance — and CISA wants federal agencies patched by September 19, 2026.

If ISE or ISE-PIC management is reachable from anywhere wider than a jump host, this is tonight’s work — not next week’s change window.

What happened

On September 16, 2026, Cisco disclosed an incorrect use of privileged APIs on an ISE / ISE-PIC endpoint. An unauthenticated remote attacker can send a crafted request, bypass the web-based management interface, and — per Cisco — may obtain command execution with root privileges.

Cisco PSIRT is aware of active exploitation. There are no workarounds; infrastructure ACLs that lock the management interface to trusted sources are the only interim control. CISA added the bug to the Known Exploited Vulnerabilities catalog the same day, with a federal due date of September 19, 2026 and forensic triage required under BOD 26-04.

Why it matters

ISE is the NAC brain: RADIUS/TACACS+, profiling, and policy over who gets on the network and at what privilege. Root on that box is a pivot primitive against every downstream authenticated segment — not a single-appliance outage.

Cisco warns a root attacker can remove or hide local evidence and strongly recommends re-imaging compromised nodes rather than trusting in-place cleanup. Release 3.0 is end-of-support with no fix — migration is the only path.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.