2026-09-17 · view entry permalink →
CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)
Cisco disclosed CVE-2026-76460 (CVSS 3.1 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) on 2026-09-16: an unauthenticated, remote attacker can bypass authentication on an API endpoint of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) due to insufficient authentication control, affecting every release "regardless of device configuration" (Cisco PSIRT, 2026-09-16). Cisco confirms the flaw was found while resolving a customer's TAC support case, not internal research, and states it is aware of active exploitation (Cisco PSIRT, 2026-09-16); a successful exploit bypasses the web-based management interface entirely and, per Cisco's own advisory, "threat actors may obtain command execution with root privileges" (Cisco PSIRT, 2026-09-16). There is no workaround; the only mitigation is restricting management-plane access via infrastructure ACLs. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; Cisco ISE 3.0 has reached End of Software Maintenance and must migrate to a supported, fixed release (Cisco PSIRT, 2026-09-16). CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day (CISA, 2026-09-16), with a remediation due date of 2026-09-19, three days out (CISA KEV JSON feed, 2026-09-16).
This CVE was part of a bundled disclosure of 15 distinct Cisco ISE advisories the same day (Cisco PSIRT, 2026-09-16). A sibling flaw, CVE-2026-76423 (CVSS 10.0, also unauthenticated and affecting every release "regardless of device configuration"), removes the same authentication boundary via a separate API endpoint, letting an attacker read or modify ISE configuration and identity data with administrative privileges; Cisco states it is "not aware of any public announcements or malicious use" of this second flaw as of disclosure, but it shares the same fixed-release schedule (Cisco PSIRT, 2026-09-16). Cisco ISE is standard 802.1X/network-access-control and identity infrastructure across enterprise and public-sector networks, so an unauthenticated bypass of its management/API surface is a direct path to defeating an organization's network access controls.
Triage: a legitimate administrative session against the ISE API originates from an authenticated, known management source; the discriminator here is that exploitation reaches the API without any authentication at all, so any successful request against the affected endpoint from outside expected management-plane sources is itself the signal, and because a root-level attacker can edit or delete access.log entries, an apparently clean on-box log is not evidence of an intact device. Cisco's guidance is to corroborate against firewall and network logs external to the ISE node for unexpected outbound uploads or downloads to unfamiliar IP addresses.
The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
This vulnerability was found during the resolution of a Cisco Technical Assistance Center (TAC) support case.
Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges.
Of the 21 vulnerabilities in total, 13 are rated critical. Based on the CVSS scores Cisco published, four vulnerabilities can be exploited remotely without authentication. (translated from Dutch)
Four vulnerabilities, CVE-2026-20130, CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460, have a CVSS score of 10.0. (translated from Dutch)
CVE-2026-76460 was one part of a much larger Cisco ISE hardening release the same day. NCSC-NL's advisory scopes 21 of the disclosed vulnerabilities and states: "Of the 21 vulnerabilities in total, 13 are rated critical. Based on the CVSS scores Cisco published, four vulnerabilities can be exploited remotely without authentication" (translated from Dutch) (NCSC-NL, 2026-09-17). Two further CVEs join the maximum-severity tier alongside the already-covered CVE-2026-76460 and CVE-2026-76423: "Four vulnerabilities, CVE-2026-20130, CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460, have a CVSS score of 10.0" (translated from Dutch) (NCSC-NL, 2026-09-17); Cisco groups multiple underlying flaws sharing a CWE classification for a hardening release under one CVE ID, with the CVSS score representing the highest-scoring underlying flaw in each bundle. CERT-FR's own combined advisory states plainly that Cisco reports only CVE-2026-76460 as actively exploited, no other CVE in the release is named exploited by any source (CERT-FR, 2026-09-17). The same advisory notes that ISE 3.1 and 3.2, both scheduled for end-of-software-maintenance on 30 November 2027, will not receive a fix at all for eight of the disclosed CVEs; any organization on those release trains has an unpatchable subset of this disclosure and should treat an upgrade to 3.3 or later as the only remediation path for those specific flaws (CERT-FR, 2026-09-17).