Attackers are actively exploiting a maximum-severity zero-day vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The flaw, tracked as CVE-2026-76460, allows remote, unauthenticated attackers to bypass authentication on affected devices by sending crafted requests to administrative API endpoints, opening a direct path to full system takeover regardless of the device’s underlying configuration.
Cisco’s Product Security Incident Response Team (PSIRT) confirmed active exploitation in the wild and urged immediate upgrades. Following the disclosure, the Cybersecurity and Infrastructure Security Agency (CISA) added the Cisco ISE zero-day to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to apply security updates within three days.
Technical Vulnerability Analysis
The security flaw stems from insufficient authentication controls on specific API endpoints in Cisco ISE and ISE-PIC. In API authentication bypass vulnerabilities of this class, request-handling middleware or API routing layers fail to enforce token validation, session checks, or access control lists before forwarding requests to backend handler functions. By crafting a specific HTTP request directly to the exposed API endpoint, an attacker circumvents the authentication barrier of the web-based management interface entirely.
Once an attacker bypasses the management interface, the flaw allows them to establish command execution with root privileges on the underlying Linux OS hosting the appliance. Obtaining root-level access on a dedicated network appliance gives adversaries complete control over the host environment. From this position, threat actors can install persistent backdoors, dump memory contents to extract credentials, manipulate administrative configuration files, and systematically clear local log files to hide their presence.
Enterprise Blast Radius and Policy Impact
Cisco Identity Services Engine serves as the centralized authorization hub for enterprise networks, managing identity-based policy, network access control (NAC), guest access, and Zero Trust security architectures. It interfaces directly with identity providers (such as Active Directory and LDAP), RADIUS/TACACS+ infrastructure, network switches, VPN concentrators, and wireless access points to enforce network segmentation.
Because ISE holds a trusted status across the entire corporate infrastructure, compromising an ISE deployment collapses the organization’s perimeter and internal access controls simultaneously. An attacker with root execution on an ISE node can:
- Bypass Network Micro-Segmentation: Modify dynamic access control lists (dACLs) or Security Group Tags (SGTs) to grant unauthorized endpoints unrestricted access to sensitive network zones, such as PCI environments or domain controllers.
- Authenticate Rogue Devices: Inject malicious entries into the policy store, allowing unauthorized or attacker-controlled devices to connect to internal enterprise networks without triggering NAC alerts.
- Harvest Enterprise Credentials: Intercept, log, or dump active identity tokens, administrative service accounts, and host keys used during authorization workflows.
- Pivot Deep into Core Infrastructure: Leverage the high-bandwidth, high-privilege network paths established between ISE nodes and critical management networks to launch lateral attacks.
This zero-day follows a pattern of threat actors targeting enterprise access management solutions. In July 2025, attackers exploited another maximum-severity zero-day in Cisco ISE (CVE-2025-20337) to achieve remote code execution and deploy a custom web shell named “IdentityAuditAction,” disguised as a legitimate ISE component. Alongside CVE-2026-76460, Cisco also patched a second critical authentication bypass (CVE-2026-76423) and five other critical flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in the same patch cycle, though those have not yet been observed in active attacks.
Mandatory Remediation and Detection Steps
Because no software workarounds or configuration mitigations exist for CVE-2026-76460, applying Cisco’s fixed software updates is the only method to secure vulnerable systems against ongoing attacks.
Due to the risk of post-exploitation log wiping by attackers operating with root privileges, security teams must combine patching with forensic analysis of external logs. Organizations deploying Cisco ISE or ISE-PIC should immediately carry out the following response protocol:
- Upgrade All Nodes Immediately: Apply the latest fixed software releases across all primary administration nodes, secondary administration nodes, policy service nodes, and monitoring nodes in the deployment.
- Inspect Node Access Logs: Examine
access.logfiles on every node within the ISE deployment for unrecognized, suspicious, or unexpected usernames attempting interactions with API endpoints or management portals. - Cross-Examine Out-of-Band Network Telemetry: Inspect perimeter firewall, web application firewall (WAF), proxy, and netflow logs for anomalous inbound connections targeting ISE management interfaces, as well as unauthorized outbound file transfers or requests to suspicious external IP addresses. External network telemetry provides an unalterable record even if an attacker cleared local host logs.
- Re-image and Restore Compromised Systems: If indicators of unauthorized access or compromised accounts are detected, standard software patching or simple file deletion is insufficient to guarantee clean operation. Cisco strongly recommends completely re-imaging compromised ISE nodes and restoring node configurations from known-clean, pre-incident backups.
Related content
Cisco Patches Maximum-Severity ISE Zero-Day Under Active Attack
Security NewsCisco Warns of Maximum-Severity ISE Zero-Day Exploited in Active Attacks
AdvisoryCritical Cisco ISE Vulnerability Exposes Networks to Unauthenticated Takeover
Security NewsCISA Adds Actively Exploited Cisco IOS CSRF Vulnerability to KEV Catalog
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call