Technology

Cisco ISE CVE-2026-76460 is actively exploited: exact patches for versions 3.1 to 3.5

Cisco says CVE-2026-76460 is actively exploited in ISE and ISE-PIC. See fixed releases for versions 3.1–3.5, CISA KEV status, mitigation and triage guidance.

Editorial illustration of a security analyst monitoring network-access and alert dashboards in a server room
Editorial illustration of a security analyst monitoring network-access and alert dashboards in a server room. Illustration: Reddy News.
Key points
  • Cisco says CVE-2026-76460 is being actively exploited and affects Cisco Identity Services Engine and Cisco ISE Passive Identity Connector regardless of device configuration.
  • Cisco's first fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; ISE 3.0 has reached End of Software Maintenance and has no patch listed for this CVE.
  • Cisco assigns a CVSS 3.1 base score of 10.0, while NVD had not published its own CVSS assessment at the publication cutoff. The score does not quantify the number of affected or compromised systems.
  • Cisco says there is no workaround. It identifies iACLs as a temporary mitigation, while describing an upgrade to a fixed release as the way to remediate the vulnerability.
  • CISA added the CVE to its Known Exploited Vulnerabilities Catalog with a 19 September 2026 due date for in-scope U.S. Federal Civilian Executive Branch agencies; that deadline is not a universal or India-specific legal requirement.

Cisco says CVE-2026-76460 is actively exploited; the fixes are available now

Cisco says CVE-2026-76460 is being actively exploited and has released fixes for Cisco Identity Services Engine, known as ISE, and Cisco ISE Passive Identity Connector, or ISE-PIC. The vendor lists these first fixed releases: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. Cisco's advisory was first published on 16 September 2026. As of the 18 September 2026, 12:45 PM IST publication cutoff, Cisco's advisory remained version 1.0 and CISA's catalog showed the CVE as a Known Exploited Vulnerability.

The issue is an authentication bypass in an ISE API. Cisco says insufficient authentication control on an API endpoint could let a remote, unauthenticated attacker obtain unauthorised access by bypassing the web-based management interface. Cisco also warns that, after successful exploitation, threat actors may obtain command execution with root privileges. The company does not identify an attacker, an attack count or affected customers in its public advisory.

Affected products and the meaning of configuration-independent exposure

The official scope is Cisco ISE and Cisco ISE-PIC, regardless of device configuration. ISE is Cisco's identity-based network access-control and policy product: it uses identity and device context to apply network access and segmentation policies. ISE-PIC is a related product named in the same advisory. The defect concerns an API connected to the affected device's web-based management interface, not a finding about every endpoint that ISE manages.

Configuration-independent means Cisco has not made exposure conditional on a particular feature, option or deployment setting within those affected products. It should not be read as proof that every ISE installation is publicly reachable or already compromised. Cisco's language establishes that an affected ISE or ISE-PIC deployment cannot be declared safe from this CVE merely because it uses a particular configuration; asset reachability and evidence of compromise remain separate questions.

Exact Cisco ISE patch releases from 3.1 through 3.5

Cisco's CVE-specific fixed-software table maps the 3.1 train to 3.1 Patch 12, the 3.2 train to 3.2 Patch 11, the 3.3 train to 3.3 Patch 12, the 3.4 train to 3.4 Patch 7 and the 3.5 train to 3.5 Patch 4. The wording matters: these are the first releases Cisco says include the fix, rather than a claim that an older patch in the same train is sufficient.

ISE 3.0 does not appear in that fixed-release table. Cisco says ISE 3.0 has reached End of Software Maintenance and advises customers to migrate to a supported release that contains the fix. Cisco's separate September ISE hardening release also says that 3.1 and 3.2 are in the Software Maintenance phase, where only Critical SIR vulnerability fixes are included. That hardening-release lifecycle context should not override the CVE-specific table, which is Cisco's authoritative mapping for this flaw.

Why Cisco rates the flaw CVSS 10.0, and the limits of that number

Cisco assigns CVE-2026-76460 a CVSS 3.1 base score of 10.0, the highest severity in that scoring system. Its vector describes a network-reachable attack with low complexity, no privileges and no user interaction, alongside high confidentiality, integrity and availability impacts. These technical characteristics help explain why an authentication bypass in a system used to enforce network identity policy has drawn urgent attention.

The 10.0 is a Cisco CNA score, not an independently calculated count of incidents or exposed devices. NIST's National Vulnerability Database displayed Cisco's 10.0 score but, at the cutoff, said an NVD assessment had not yet been provided. A CVSS score also does not say how many systems are internet-accessible, how many were targeted or whether a particular organisation has been breached. Those distinctions are important when treating severity, exploitation and impact as separate facts.

No workaround means no workaround; iACLs are a temporary mitigation

Cisco states that there are no workarounds that address this vulnerability. It nevertheless describes a mitigation: infrastructure access control lists, or iACLs, can be used to allow only required management and control-plane traffic that is destined for the affected device. The purpose is to reduce the opportunity for remote exploitation while a fixed release is put in place.

That distinction is not semantic. A workaround would resolve or bypass the underlying product defect, while the iACL approach restricts which traffic can reach the device. Cisco says mitigations are temporary solutions until an upgrade to fixed software is available, and in this case the company has already made fixed releases available. Network rules can also have operational consequences, so implementation needs to follow the organisation's approved change and incident procedures rather than being treated as a universal substitute for the patch.

Cisco's published log and recovery guidance if compromise is suspected

Cisco's indicators-of-compromise section tells administrators to review access.log for suspicious usernames. For distributed deployments, it says this review should cover every node. Cisco also explains that additional access logs can be obtained through a support bundle that includes debug logs. The vendor presents its example as non-exhaustive: a suspicious entry can indicate malicious activity, but the absence of one does not settle the question of whether a system was targeted.

The caution is especially important because Cisco says successful exploitation may give a threat actor root-level command execution, which may allow evidence or indicators of compromise to be removed or hidden. Cisco therefore strongly recommends cross-checking network and firewall logs outside the impacted device, including for unexpected uploads from the device to external IP addresses or downloads from malicious IP addresses. If malicious activity is suspected, Cisco strongly recommends re-imaging affected nodes and restoring from a configuration backup if needed. This describes Cisco's product-specific guidance, not evidence that any particular deployment has been compromised.

CISA KEV listing and the 19 September federal deadline

CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities Catalog on 16 September 2026. The entry gives a due date of 19 September 2026, marks forensic triage as required and records ransomware-campaign use as unknown. CISA describes the required action as applying mitigations under vendor instructions and the BOD 26-04 risk-based guidance, following its forensic-triage requirements, and evaluating each asset's internet exposure. The listing is official confirmation that CISA has evidence of active exploitation; it does not publicly identify who is responsible or how broadly the flaw has been used.

The date is a compliance deadline for U.S. Federal Civilian Executive Branch agencies within the scope of Binding Operational Directive 26-04. CISA says that directive applies only to those agencies and their applicable federal information systems, not automatically to private companies, Indian organisations or every U.S. government system. CISA encourages all organisations to use risk-based vulnerability management and to prioritise KEV items, but encouragement is different from the directive's binding obligation. The 19 September date is therefore a useful urgency signal for other defenders, not a universal legal deadline.

CVE-2026-76460 is not the Cisco Secure Email Gateway flaw CVE-2026-76461

Cisco published another actively exploited critical vulnerability, CVE-2026-76461, in the same week. The identifiers are close, but the incidents are different. CVE-2026-76460 concerns authentication control in an API of Cisco ISE and ISE-PIC. CVE-2026-76461 concerns insufficient validation in email parsing in Cisco AsyncOS Software for Cisco Secure Email Gateway, which Cisco describes as a SQL-injection vulnerability.

The distinction changes the affected product, the investigation path and the patch path. Cisco rates the Secure Email Gateway issue 9.8 under CVSS 3.1 and lists AsyncOS fixed releases, while the ISE issue is rated 10.0 and uses the five ISE or ISE-PIC patch levels above. Teams that own both product families need to track the two vendor advisories separately; a remediation record for one CVE is not evidence that the other product is fixed.

What official sources and independent reporting establish, and what remains unknown

Cisco's advisory establishes the affected product family, authentication-bypass description, Cisco's 10.0 score, active-exploitation statement and fixed-release mapping. The CISA KEV entry establishes the 16 September addition and 19 September due date, while the CVE record reproduces Cisco-provided description and CVSS information. Independent reports by BleepingComputer and Help Net Security describe the same vendor disclosure and repeat Cisco's warning to examine access logs and outside network records. Their reporting is useful corroboration that the disclosure has been publicly tracked, but it is not an independent replication of exploitation or a forensic account of an attack.

Public materials through the cutoff do not name a threat actor, give a victim list, state a number of attacks, disclose an exploitation method beyond Cisco's high-level description, or establish widespread compromise. Neither the CVSS number nor the KEV label fills those gaps. The practical analysis is narrower: a configuration-independent defect with vendor-confirmed active exploitation, a maximum Cisco severity rating and available fixed releases deserves priority handling by organisations that operate the named Cisco products. This article is a news explainer and does not replace vendor guidance, incident response or professional security advice.

Reader guide

Article questions, answered

Short answers to common reader questions based on the reporting above.

Which Cisco ISE releases contain the fix for CVE-2026-76460?

Cisco lists the first fixed releases as ISE or ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. These are first fixed releases, so an organisation should use Cisco's current compatibility and upgrade guidance when selecting its destination release. Cisco's CVE-specific advisory does not provide a 3.0 patch; it says ISE 3.0 has reached End of Software Maintenance and customers should migrate to a supported release that includes the fix.

Are infrastructure access control lists a workaround for this Cisco ISE bug?

No. Cisco explicitly says there is no workaround that addresses CVE-2026-76460. It describes infrastructure access control lists, or iACLs, as a temporary mitigation that can limit remote exploitation by allowing only required management and control-plane traffic destined for the affected device. Cisco still identifies upgrading to a fixed release as the remediation.

What triage guidance has Cisco published if an ISE deployment may have been targeted?

Cisco says to review access.log files for suspicious usernames and to do so on every node in a distributed deployment. It also says defenders should cross-check network and firewall logs outside the affected device, because an attacker with root-level command execution may remove or hide local evidence. If malicious activity is suspected, Cisco strongly recommends re-imaging affected nodes and restoring from a configuration backup if needed. These are Cisco's product-specific incident-response recommendations, not a finding that every affected installation has been compromised.

Is CVE-2026-76460 the same issue as Cisco Secure Email Gateway CVE-2026-76461?

No. CVE-2026-76460 is an authentication-bypass vulnerability in an API of Cisco Identity Services Engine and ISE Passive Identity Connector. CVE-2026-76461 is a separate SQL-injection vulnerability in email parsing in Cisco AsyncOS Software for Cisco Secure Email Gateway. They affect different products, have different Cisco advisory IDs and use different fixed-release paths.

Sources and further reading

These references support the factual context used in this article. Links open the original publisher.

  1. Cisco Identity Services Engine Authentication Bypass VulnerabilityCisco · accessed 18 September 2026
  2. CVE-2026-76460 DetailNIST National Vulnerability Database · accessed 18 September 2026
  3. Known Exploited Vulnerabilities Catalog: CVE-2026-76460Cybersecurity and Infrastructure Security Agency · accessed 18 September 2026
  4. CISA Adds Two Known Exploited Vulnerabilities to CatalogCybersecurity and Infrastructure Security Agency · accessed 18 September 2026
  5. BOD 26-04: Prioritizing Security Updates Based on RiskCybersecurity and Infrastructure Security Agency · accessed 18 September 2026
  6. BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on RiskCybersecurity and Infrastructure Security Agency · accessed 18 September 2026
  7. Cisco Identity Services Engine Hardening Release: September 2026Cisco · accessed 18 September 2026
  8. Cisco Secure Email Gateway SQL Injection VulnerabilityCisco · accessed 18 September 2026
  9. Cisco warns of max severity ISE zero-day exploited in attacksBleepingComputer · accessed 18 September 2026
  10. Unauthenticated attackers are bypassing Cisco ISE's management interface (CVE-2026-76460)Help Net Security · accessed 18 September 2026
  11. CVE-2026-76460CVE Program · accessed 18 September 2026