A maximum-severity authentication bypass in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), caused by insufficient authentication control on an API endpoint. NVD scores it 10.0 (Critical, CVSS 3.1) and records the CVE as analysed; Cisco states the flaw is under active exploitation and CISA added it to the Known Exploited Vulnerabilities catalogue on 16 September 2026 with a 19 September remediation deadline for federal civilian agencies.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-76460 |
| CVSS | 10.0 (Critical, CVSS 3.1) |
| Vendor / product | Cisco / Identity Services Engine (ISE) and ISE-PIC |
| Reported | 2026-09-17 |
An unauthenticated, remote attacker sends a crafted request to the affected API endpoint and bypasses the web-based management interface. Cisco states that successful exploitation can yield command execution with root privileges, which means evidence of the intrusion may be removed or hidden. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. There is no workaround; the only interim mitigation is infrastructure ACLs that restrict management and control-plane traffic to the device. Cisco's detection guidance is to review access.log on every node of a distributed deployment for unexpected usernames β a hit indicates likely compromise, and affected nodes should be re-imaged and restored from configuration backup.