Cisco has warned of a maximum-severity security vulnerability in its Identity Services Engine (ISE) that is being actively exploited in the wild.
Tracked as CVE-2026-76460, the flaw carries a CVSS score of 10.0 and could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to affected systems.
The vulnerability is caused by insufficient authentication controls on an API endpoint. According to Cisco, an attacker could exploit the issue by sending a specially crafted request to the affected endpoint, potentially bypassing the web-based management interface and gaining unauthorized access to the device.
The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. Cisco has released fixes across supported versions, with the vulnerability addressed in ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.
Cisco said it is aware of active exploitation and urged customers to upgrade to a fixed software release. The company has not disclosed details about the attackers or the specific campaigns using the vulnerability.
The company is also advising administrators to check the access.log file for suspicious usernames as a potential indicator of compromise. For distributed deployments, logs from every node should be reviewed. Cisco provided a command that administrators can use to search for unexpected activity: admin#show logging application ise-kong/access.log | include dummyuser. The presence of an entry matching the search could indicate malicious activity.
If exploitation is detected, Cisco recommends re-imaging affected nodes and restoring them from a configuration backup where necessary. The company warned that successful exploitation could give attackers command execution with root privileges, meaning threat actors may also be able to remove or hide evidence of their activity.
There is currently no workaround for the vulnerability. As a mitigation, Cisco recommends using infrastructure access control lists (iACLs) to restrict management and control-plane traffic reaching affected devices to only the traffic that is required.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, 2026. Federal Civilian Executive Branch agencies have been given until September 19, 2026, to apply the required fixes.
The disclosure comes shortly after Cisco warned that another critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway, tracked as CVE-2026-76461 with a CVSS score of 9.8, was also being actively exploited.
Cisco has also released fixes for dozens of other vulnerabilities across its product portfolio. The company said 77 new CVEs were issued Wednesday, including 41 affecting ISE and 28 involving the Secure Firewall portfolio. Several of the vulnerabilities can lead to command injection, authentication or authorization bypass, SQL injection, remote code execution, root access, information disclosure and denial-of-service conditions.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
While the other vulnerabilities have not been reported as actively exploited, Cisco’s latest security updates highlight the need for administrators to prioritize patching, particularly for internet-accessible management systems and products containing vulnerabilities that could provide attackers with privileged access.



