Advisories
Cisco ISE Zero‑Day Exploited in the Wild – Immediate Patch Required
Cisco’s Identity Services Engine (ISE) is under attack. The CVE‑2026‑76460 vulnerability, rated maximum severity, lets remote actors bypass authentication by sending crafted API requests. Cisco has released fixed releases for ISE and ISE‑PIC, but no workarounds exist. The company urges customers to apply the patch immediately, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies patch within three days.
Cisco’s Identity Services Engine (ISE) is a central hub for enforcing Zero Trust policies, managing endpoints, users, and device access. A newly disclosed flaw, CVE‑2026‑76460, undermines this foundation by allowing attackers to bypass the web‑based management interface and gain unauthorized access to the device.
What the Vulnerability Looks Like
- Insufficient authentication control on an API endpoint in Cisco ISE and ISE‑PIC.
- Exploited via a crafted request that bypasses normal login checks.
- Successful exploitation grants attackers root‑level command execution.
Active Exploitation in the Wild
Threat actors are already leveraging this weakness to compromise networks. Cisco’s Product Security Incident Response Team (PSIRT) confirmed active exploitation and flagged the issue as “actively exploited.”
"The vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint," the company explained.
Cisco’s Fixes
- Fixed releases:
- 3.1 – Patch 12
- 3.2 – Patch 11
- 3.3 – Patch 12
- 3.4 – Patch 7
- 3.5 – Patch 4
- Other critical CVEs addressed in the same update: CVE‑2026‑76423, CVE‑2026‑20176, CVE‑2026‑20211, CVE‑2026‑20307, CVE‑2026‑20284.
What You Should Do Now
- Apply the latest patch immediately – no workarounds exist.
- Inspect
access.logon every ISE node for suspicious usernames. - Cross‑check firewall and network logs for anomalous traffic to or from external IPs.
- If malicious activity is suspected, re‑image the node and restore from a known‑good backup.
- Follow CISA’s guidance: federal agencies must patch within three days of the KEV listing.
Historical Context
Over the past five years, CISA has identified 99 actively exploited Cisco flaws, including seven that were weaponized in ransomware campaigns. In July 2025, a separate ISE zero‑day (CVE‑2025‑20337) was used to deploy a disguised web shell for remote code execution.