Security advisories

Maximum Severity Zero-Day Vulnerability Impacting Cisco ISE and ISE-PIC (CVE-2026-76460)

September 17, 2026

3 MINS READ

THE THREAT

On September 16th, 2026, Cisco disclosed CVE-2026-76460, a critical authentication bypass zero-day vulnerability impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) products. CVE-2026-76460 (CVSS: 10) is due to insufficient authentication control on an API endpoint and can allow an attacker to gain unauthorized access through bypassing the web-based management interface. The vulnerability impacts versions 3.1, 3.2, 3.3, 3.4, and 3.5 of Cisco ISE and ISE-PIC regardless of device configuration; patches have been released to address the flaw.

At the time of disclosure, Cisco stated that they are "aware of active exploitation" of CVE-2026-76460. As exploitation is ongoing, organizations that utilize the impacted software must apply relevant patches immediately.

What We're Doing About It

What You Should Do About It

Additional Information

Exploitation of CVE-2026-76460 involves an attacker sending a specially crafted request to an affected API endpoint, where they can obtain unauthorized access. This access can then be leveraged to perform further malicious activity. Although Cisco indicated that exploitation of the vulnerability has been observed in the wild, no specific details on the attacks were shared. Cisco advises organizations to review relevant access logs to identify any suspicious usernames, which could be an indicator of attempted exploitation. Restricting access to impacted devices to trusted IP addresses only is a temporary mitigation step until patches can be applied.

Following Cisco's disclosure, CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, giving Federal Civilian Executive Branch (FCEB) agencies a deadline of September 19th to apply relevant patches. At the time of writing, technical details on CVE-2026-76460 are limited, and there are no reports of publicly available Proof-of-Concept (PoC) exploit code, which can often be an early warning sign of widespread exploitation. As vulnerabilities impacting Cisco ISE and ISE-PIC have a history of being targeted within attacks, organizations should ensure that patches are applied as soon as possible.

Impacted Product List

Impacted Product List
Product Vulnerable Version First Fixed Release
Cisco ISE and ISE-PIC 3.1 3.1 Patch 12
3.2 3.2 Patch 11
3.3 3.3 Patch 12
3.4 3.4 Patch 7
3.5 3.5 Patch 4

References:
[1]  https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
[2] https://nvd.nist.gov/vuln/detail/cve-2026-76460
[3] https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog
[4] https://www.esentire.com/security-advisories/sonicwall-discloses-two-zero-day-vulnerabilities-cve-2026-15409-cve-2026-15410
[5] https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/ 
 

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories