First Seen: September 16, 2026
Affected Products: Cisco Identity Services Engine (ISE), Cisco ISE Passive Identity Connector (ISE-PIC)
Impact: Cisco has confirmed that a critical flaw in its Identity Services Engine (ISE), the platform many organizations rely on to decide who and what is allowed onto their network, is being actively exploited. Tracked as CVE-2026-76460 and carrying the maximum CVSS score of 10.0, the vulnerability lets a remote attacker slip past authentication entirely by sending a specially crafted request to a vulnerable API endpoint. Both Cisco ISE and its companion ISE Passive Identity Connector (ISE-PIC) are affected regardless of how they are configured. Cisco has not named the attackers or shared details of the campaign, but it has warned that a successful exploit can hand an intruder command execution with root privileges; it is essential to patch, as the exploitation is active.
CVE
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | Cisco ISE & ISE-PIC | Yes | Yes | Yes |
Vulnerability Details
Vulnerability
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-76460 | Cisco ISE & ISE-PIC (Releases 3.0 through 3.5, before the first fixed release) | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:* | CWE-648 |
Recommendations
Upgrade every affected node to the first fixed release for your train: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4. Release 3.0 has reached end of software maintenance and must be migrated to a supported, fixed release. Because the flaw is under active attack and there is no full workaround, patching should be treated as an emergency change.
On every node in the deployment, review the ISE access logs for suspicious or unexpected usernames — this must be done per node in a distributed deployment. Also cross-check firewall and network logs kept off the device for unusual activity. If any sign of malicious activity is found, re-image the affected nodes and restore from a known-good configuration backup.
Where you cannot patch immediately, restrict who can even reach the device. Use infrastructure access control lists (iACLs) to permit only the required management and control-plane traffic destined for ISE. This does not fix the vulnerability but shrinks the attack surface while you schedule the upgrade.
A successful exploit can grant root-level command execution, so a confirmed hit should be assumed to be a full appliance compromise rather than a contained event. Do not attempt to clean in place — rebuild from trusted media and restore configuration from backup, then rotate any credentials, certificates, or secrets that the node held.
Potential MITRE ATT&CK TTPs
Patch Link
References
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
